From 105354a2ce0c835fef8f91ba75d23923715f37ab Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Sat, 3 Oct 2026 15:45:37 +0000 Subject: [PATCH] Site: homepage with animations and live journey, litepaper page, Vercel config; commit email matched to GitHub Co-Authored-By: Claude Fable 5.1 --- proto-metal/main.swift | 209 +++++++++++++++++- site/.gitignore | 2 + site/index.html | 478 +++++++++++++++++++++++++++++++++++++++++ site/journey.json | 19 ++ site/litepaper.html | 453 ++++++++++++++++++++++++++++++++++++++ site/vercel.json | 13 ++ 6 files changed, 1172 insertions(+), 2 deletions(-) create mode 100644 site/.gitignore create mode 100644 site/index.html create mode 100644 site/journey.json create mode 100644 site/litepaper.html create mode 100644 site/vercel.json diff --git a/proto-metal/main.swift b/proto-metal/main.swift index 7fb1958f..87748917 100644 --- a/proto-metal/main.swift +++ b/proto-metal/main.swift @@ -25,7 +25,14 @@ struct Options { var determinism = false // --determinism: 5 identical GPU runs + double compile var memcheck = false // --memcheck: static mask check + 4 MiB run with wrapping nonces // Shortcut measurement (bench variant, not a test): compute dataset elements inline instead of loading them. + // Closed-form mode: every load computes ds_elem. Memory-hard mode: every load derives the item from the cache. var inlineDataset = false + // Dataset construction (added 3 October 2026). Default is the memory-hard cache construction (MEMHARD.md); + // --closed-form selects the original six-operation closed form so the two can be compared. + var closedForm = false + // Generator levers (MEMHARD.md section 7). Defaults reproduce the original generator exactly. + var loadWeight = 25 // --load-weight W: percent weight of the load op (default 25) + var wideFrac = 0 // --wide-frac P: percent of load instructions emitted as warp-coalesced wide loads var anyTest: Bool { fuzz != nil || edge || stats || determinism || memcheck } } @@ -52,10 +59,16 @@ func parseArgs() -> Options { case "--determinism": o.determinism = true case "--memcheck": o.memcheck = true case "--inline-dataset": o.inlineDataset = true + case "--closed-form": o.closedForm = true + case "--load-weight": o.loadWeight = Int(take()) ?? o.loadWeight + case "--wide-frac": o.wideFrac = Int(take()) ?? o.wideFrac case "-h", "--help": print(""" igneum-bench [--seed ] [--hours N] [--batch-log2 22] [--batches 4] [--dataset-log2 28] [--verify-warps 3] [--dump ] [--day ] + [--closed-form] original closed-form dataset (default: memory-hard cache construction, see MEMHARD.md) + [--load-weight W] generator lever (a): percent weight of the load op (default 25) + [--wide-frac P] generator lever (b): percent of loads emitted as warp-coalesced 128-byte loads (default 0) [--export-pack ] write the CUDA program pack for --seed, then exit hardening tests (run instead of the bench; several may be combined; exit 0 only if all pass): [--fuzz N [--fuzz-seed ]] N random programs, GPU vs CPU, 4 random warps each, @@ -130,9 +143,197 @@ struct SplitMix64 { mutating func below(_ n: Int) -> Int { Int(next() % UInt64(n)) } } +// MARK: - Memory-hard dataset (added 3 October 2026, spec in MEMHARD.md) +// +// Cache: 2^26 words (256 MiB) = 2^22 lines of 16 words, in 2^16 segments of 64 lines. Each segment is a +// sequential chain of ChaCha12 blocks with feed-forward: in_j = prev_line ^ (sigma || K || seg || j || tag), +// line_j = core(in_j) + in_j, prev_0 = 0. Recomputing line j costs j + 1 block evaluations. +// Item t (16 words = 64 bytes): s = (K[0..7], t * MUL[i] + RC[i]), then 8 rounds of +// s = M_r(s); a = s[0] & (2^22 - 1); s ^= cache line a +// and a final M_8. M_r is the seed-parameterised mixer: per word (s ^ (RC + (r+1) * 0x9E3779B9)) * MUL, +// then one ChaCha-shaped column round and diagonal round with seed-drawn rotations. +// Dataset word w = item(w >> 4)[w & 15]. The hash kernel is unchanged: it still does dataset[r & MASK]. + +let cacheLog2Words = 26 +let cacheSegmentLog2Lines = 6 +let cacheWords = 1 << cacheLog2Words +let cacheLines = cacheWords >> 4 +let cacheLinesPerSegment = 1 << cacheSegmentLog2Lines +let cacheSegments = cacheLines >> cacheSegmentLog2Lines +let cacheLineMask = UInt32(cacheLines - 1) +let itemRounds = 8 +let chachaRounds = 12 +let chachaSigma: [UInt32] = [0x61707865, 0x3320646e, 0x79622d32, 0x6b206574] +let cacheTag: [UInt32] = [0x49676e65, 0x756d4d48] // "Igne", "umMH" + +// Rotation without the n == 0 check: every caller passes 1..31. +@inline(__always) func rotlc(_ x: UInt32, _ n: UInt32) -> UInt32 { (x << n) | (x >> (32 - n)) } + +@inline(__always) func qr(_ s: UnsafeMutablePointer, _ a: Int, _ b: Int, _ c: Int, _ d: Int, + _ r1: UInt32, _ r2: UInt32, _ r3: UInt32, _ r4: UInt32) { + s[a] = s[a] &+ s[b]; s[d] ^= s[a]; s[d] = rotlc(s[d], r1) + s[c] = s[c] &+ s[d]; s[b] ^= s[c]; s[b] = rotlc(s[b], r2) + s[a] = s[a] &+ s[b]; s[d] ^= s[a]; s[d] = rotlc(s[d], r3) + s[c] = s[c] &+ s[d]; s[b] ^= s[c]; s[b] = rotlc(s[b], r4) +} + +// y = ChaCha12 core(x) + x. Standard quarter-round rotations 16, 12, 8, 7; column then diagonal. +@inline(__always) func chachaBlock(_ x: UnsafePointer, _ y: UnsafeMutablePointer) { + for i in 0..<16 { y[i] = x[i] } + for _ in 0..<(chachaRounds / 2) { + qr(y, 0, 4, 8, 12, 16, 12, 8, 7); qr(y, 1, 5, 9, 13, 16, 12, 8, 7) + qr(y, 2, 6, 10, 14, 16, 12, 8, 7); qr(y, 3, 7, 11, 15, 16, 12, 8, 7) + qr(y, 0, 5, 10, 15, 16, 12, 8, 7); qr(y, 1, 6, 11, 12, 16, 12, 8, 7) + qr(y, 2, 7, 8, 13, 16, 12, 8, 7); qr(y, 3, 4, 9, 14, 16, 12, 8, 7) + } + for i in 0..<16 { y[i] = y[i] &+ x[i] } +} + +// Mixer parameters drawn from the day key. Draw order: ROT[0..7] (1..31), MUL[0..15] (odd), RC[0..15]. +final class MixParams { + let key: UnsafeMutablePointer // 8 + let rot: UnsafeMutablePointer // 8 + let mul: UnsafeMutablePointer // 16 + let rc: UnsafeMutablePointer // 16 + let keyWords: [UInt32] + var rotWords: [UInt32] { (0..<8).map { rot[$0] } } + var mulWords: [UInt32] { (0..<16).map { mul[$0] } } + var rcWords: [UInt32] { (0..<16).map { rc[$0] } } + init(key k: [UInt32]) { + precondition(k.count == 8) + keyWords = k + key = UnsafeMutablePointer.allocate(capacity: 8) + rot = UnsafeMutablePointer.allocate(capacity: 8) + mul = UnsafeMutablePointer.allocate(capacity: 16) + rc = UnsafeMutablePointer.allocate(capacity: 16) + for i in 0..<8 { key[i] = k[i] } + var rng = SplitMix64(s: UInt64(k[0]) | (UInt64(k[1]) << 32)) + for i in 0..<8 { rot[i] = UInt32(1 + rng.below(31)) } + for i in 0..<16 { mul[i] = UInt32(truncatingIfNeeded: rng.next()) | 1 } + for i in 0..<16 { rc[i] = UInt32(truncatingIfNeeded: rng.next()) } + } +} + +// M_r on 16 words in place. rk = (r + 1) * 0x9E3779B9 mod 2^32. +@inline(__always) func mixer(_ s: UnsafeMutablePointer, _ rk: UInt32, _ mp: MixParams) { + let mul = mp.mul, rc = mp.rc, R = mp.rot + for i in 0..<16 { s[i] = (s[i] ^ (rc[i] &+ rk)) &* mul[i] } + qr(s, 0, 4, 8, 12, R[0], R[1], R[2], R[3]); qr(s, 1, 5, 9, 13, R[0], R[1], R[2], R[3]) + qr(s, 2, 6, 10, 14, R[0], R[1], R[2], R[3]); qr(s, 3, 7, 11, 15, R[0], R[1], R[2], R[3]) + qr(s, 0, 5, 10, 15, R[4], R[5], R[6], R[7]); qr(s, 1, 6, 11, 12, R[4], R[5], R[6], R[7]) + qr(s, 2, 7, 8, 13, R[4], R[5], R[6], R[7]); qr(s, 3, 4, 9, 14, R[4], R[5], R[6], R[7]) +} + +@inline(__always) func roundKey(_ r: Int) -> UInt32 { UInt32(r + 1) &* 0x9E3779B9 } + +// One segment of the cache: 64 chained lines written at cache[seg * 1024 ...]. +func cpuFillSegment(_ cache: UnsafeMutablePointer, seg: Int, key: UnsafePointer) { + var inp = [UInt32](repeating: 0, count: 16) + inp.withUnsafeMutableBufferPointer { ib in + let x = ib.baseAddress! + var prev: UnsafePointer? = nil + for j in 0.., key: [UInt32]) -> Double { + let t0 = nowNs() + key.withUnsafeBufferPointer { kb in + for seg in 0.., _ n: Int, _ mp: MixParams, cache: UnsafePointer, out: UnsafeMutablePointer) { + let key = mp.key, mul = mp.mul, rc = mp.rc + for k in 0..) -> [UInt32] { + var out = [UInt32](repeating: 0, count: 16) + var tt = t + out.withUnsafeMutableBufferPointer { ob in deriveItems(&tt, 1, mp, cache: cache, out: ob.baseAddress!) } + return out +} + +// The CPU verifier's view of the memory-hard dataset: the 256 MiB cache and nothing else. +final class MemhardCPU { + let mp: MixParams + let cache: UnsafeMutablePointer + let fillMs: Double + private let items = UnsafeMutablePointer.allocate(capacity: 64 * 16) + private let uniq = UnsafeMutablePointer.allocate(capacity: 64) + private let slot = UnsafeMutablePointer.allocate(capacity: 64) + var derivations = 0 // items derived so far (statistics) + init(key: [UInt32]) { + mp = MixParams(key: key) + cache = UnsafeMutablePointer.allocate(capacity: cacheWords) + fillMs = cpuFillCache(cache, key: key) + } + func word(_ w: UInt32) -> UInt32 { deriveItem(w >> 4, mp, cache: UnsafePointer(cache))[Int(w & 15)] } + // out[k] = dataset[idx[k]] for k < n (n <= 64). Equal items are derived once. + func fetch(_ idx: UnsafePointer, _ n: Int, _ out: UnsafeMutablePointer) { + var u = 0 + for k in 0..> 4 + var found = -1 + for j in 0.. UInt32 { memhard?.word(w & mask) ?? datasetElem(w & mask, day.0, day.1) } + func fetch(_ idx: UnsafePointer, _ n: Int, _ out: UnsafeMutablePointer) { + if let m = memhard { m.fetch(idx, n, out) } + else { for k in 0.. 0. +enum Op: String { case add, sub, mul, mulhi, xor, or, rotl, rotr, mad, shfl, load, wload } struct Instr { var op: Op @@ -152,7 +353,11 @@ struct Program { let instrs: [Instr] static let iterations = 8 static let count = 64 - var loadsPerHash: Int { instrs.filter { $0.op == .load }.count * Program.iterations } + var loadsPerHash: Int { instrs.filter { $0.op == .load || $0.op == .wload }.count * Program.iterations } + var wideLoadsPerHash: Int { instrs.filter { $0.op == .wload }.count * Program.iterations } + var hasWide: Bool { instrs.contains { $0.op == .wload } } + // Distinct dataset items a 32-lane warp touches per hash: 32 per plain load, 2 per wide load (128 B = 2 items). + var itemsPerWarp: Int { (loadsPerHash - wideLoadsPerHash) * 32 + wideLoadsPerHash * 2 } var histogram: [(String, Int)] { var d = [String: Int]() for i in instrs { d[i.op.rawValue, default: 0] += 1 } diff --git a/site/.gitignore b/site/.gitignore new file mode 100644 index 00000000..245259b6 --- /dev/null +++ b/site/.gitignore @@ -0,0 +1,2 @@ +.vercel +.env* diff --git a/site/index.html b/site/index.html new file mode 100644 index 00000000..aa107d5b --- /dev/null +++ b/site/index.html @@ -0,0 +1,478 @@ + + + + + +Igneum + + + + + + + + + + + + + + +
+ +
+
+
GPUs are back · for good
+

Mined by GPUs.
Proven by fire.

+

The first chain built so no chip can ever take your place. A mining program that rewrites itself every hour, so no chip can be built for it. The same card proves every block and gets paid for it. No premine, no stake, no foundation, no merge to anything else, ever.

+ +
+
+
+
This tab · light client
+
PREVIEW
+
+
+
+
+

Your browser will verify Igneum

+

One proof checked here, in milliseconds. No node, no trust, no middleman. Live at testnet.

+
+
+
+
BLOCK PROOF
prototype
+
CHECKPOINT
locked by miners
+
PROOF SYSTEM
version 1
+
VERIFIED TODAY
at testnet
+
+
+
+
+ +
+
+
1 / s
blocks, rising to 10
+
~60 s
to a verified proof at launch
+
0
premine, pre-sale, allocation
+
4B
IGN hard cap, ever
+
100%
of emission to miners and provers
+
+
+ +
+
+
+

Watch the chain prove itself

+

Blocks arrive every second. Miners prove them in shards. A checkpoint locks every 30 seconds. All of it will be on this page, live.

+
+
+
+
+ proven + being proven by miners + just mined + checkpoint locked by sustained miners +
+
+
+
+
This hour's mining program
next in 59:59
+

+        

A new random program every hour. A GPU compiles it in seconds. A chip designed for last hour's program is already obsolete.

+
+
+
Proofs sold to other chains
+
+
rollup · batch proofat testnet
+
bridge · state proofat testnet
+
rollup · fault proofat testnet
+
IGN burned from jobsat launch
+
+

The same cards that secure Igneum sell proofs to rollups and bridges. 10% of every job fee is burned.

+
+
+
+
+ +
+
+
+

Monero's idea, finished for GPUs

+

RandomX has kept chips off Monero since 2019 by making the mining program random. Igneum takes the same principle to graphics cards and adds the parts RandomX never had.

+
+
+ + + + + + + + + + + + +
PropertyRandomX, MoneroIgneum
Hardware it is built forCPUs. GPUs run it badly on purposeGPUs. Any card, any vendor. Bit-exact on Apple and NVIDIA, measured
Random programPer hash, interpreted in a virtual machinePer hour, compiled to native GPU code, with a per-hash random data path
DatasetAbout 2 GB, the same size since 2019, approximate2 GB at genesis, growing every year past any chip's memory
Light verification256 MB cache on a CPU, milliseconds256 MB cache on a CPU, one warp under 10 ms, the measured gate
Changes over timeNone. A fixed design, unchanged for seven yearsAutomatic era draws and a reserve of instruction families that unlock by height. Nobody touches it
Seed grindingNot applicable, the program comes from the hash inputClosed by a verifiable delay between seed and program
Useful workNone. Hashing onlyThe same card proves every block and sells proofs to other chains
Track recordNo chip in seven yearsZero years. Every number above is measured, published, and reproducible from the repository
+
+

RandomX proved that a random program beats a chip when the only hardware that runs it well is the hardware everyone already owns. Igneum does the same for the card in your PC, and makes the program keep moving without a human. Run the benchmark on your own card from the repository and post the number.

+
+
+ +
+
+

One chain, three jobs

+
+
+ +

Mine

+

Any card with 4 GB today, 8 GB for the next decade. A random program every hour, so there is nothing for a chip to be built for. 80% of every block to the miner who finds it, from block one.

+ Get the miner +
+
+ +

Prove

+

The same card proves shards of every block and sells proofs to other chains. A proof is right or it is not, so nobody has to trust a miner, ever.

+ How proving pays +
+
+ +

Build

+

Ethereum bytecode, wallets and tools, unchanged. One-second inclusion, finality in about two minutes, a prover network any contract can call, and 15% of the priority fees your code earns paid back to you every block.

+ Deploy on Igneum +
+
+
+
+ +
+
+
+

Three ways a card gets paid

+

One client, one balance. The miner software switches the card between hashing and proving by itself.

+
+
+
01

Block reward

80% of emission to the miner who wins the block. Half of all IGN is mined in the first two years.

+
02

Proving the chain

20% of emission plus a share of every block's gas, paid to the cards that prove shards and aggregate them.

+
03

Proving for others

Rollups and bridges pay for proofs in their own money. Small market today, growing with every chain that moves to proofs. Upside, not a promise.

+
+
+ Windows + macOS + Linux + HiveOS +

One click: install, press start, the card mines and proves to a wallet the app makes for you. Available at public testnet. Open source, 1% dev fee like every miner you already run.

+
+
+
+ +
+
+
+
+

Where Igneum is right now

+
LOADING
+
+

Thirteen months, four public gates. Every gate is a measurement, published whether it passes or fails. Miss it and the phase repeats or Igneum stops.

+
+
+
+
+
+ +
+
+
+

Every coin, mined

+

Hard cap of 4 billion IGN. Emission halves every two years for ever. Not one coin to a founder, a fund or a stake. Development is paid from fees by the people who use the chain, and spent only when miners signal yes.

+
+
+
+ 80% miners + 20% provers + 0% anyone else +
+
+
+
+
0
premine
+
0
stake in consensus
+
0
admin keys
+
90%
of blocks must signal before any upgrade
+
+
+
+ +
+
+
+

Read what Igneum does not claim.

+

The litepaper states the limits before anyone else does. Proof lag, chip economics, the market size, and the one rule external review will try hardest to break.

+
+ Litepaper +
+
+ + + + + + diff --git a/site/journey.json b/site/journey.json new file mode 100644 index 00000000..f6753675 --- /dev/null +++ b/site/journey.json @@ -0,0 +1,19 @@ +{ + "updated": "2026-10-03", + "stage": "phase-2", + "phases": [ + { "id": "phase-1", "name": "Specification", "when": "Oct to Nov 2026", "status": "active", "line": "Mining generator, shard proving, finality rules, written for external review" }, + { "id": "phase-2", "name": "Prove the proving", "when": "Nov 2026 to Jan 2027", "status": "active", "line": "Mining program prototype on GPU and CPU, shard proving benchmark on consumer cards", "gate": "A mid-range GPU proves a shard in under 20 s and a CPU verifies a hash in 10 ms" }, + { "id": "phase-3", "name": "Devnet", "when": "Feb to Mar 2027", "status": "next", "line": "BlockDAG node with the new mining program and EVM execution, 20 nodes", "gate": "1 block a second held with proofs under 60 s behind the tip" }, + { "id": "phase-4", "name": "Finality and job market", "when": "Apr to Jul 2027", "status": "next", "line": "Sustained-mining finality, external proving jobs, miner client with auto-switching", "gate": "Finality design passes external review and one rollup signs for testnet" }, + { "id": "phase-5", "name": "Public testnet", "when": "Aug to Oct 2027", "status": "next", "line": "One-click miner app on Windows, macOS and Linux, HiveOS, pools, the first rollup as a proving customer, no coin yet", "gate": "1,000 independent miners run 30 days and rollup proofs are delivered on time" }, + { "id": "phase-6", "name": "Mainnet fair launch", "when": "Nov 2027", "status": "next", "line": "Genesis with no premine, 30-day ramp, exchange listings after" } + ], + "log": [ + { "date": "2026-10-03", "text": "RTX 5090 ran two generated programs and matched the Apple M5 Max hash for hash, 192 of 192. Vendor independence measured on two vendors." }, + { "date": "2026-10-03", "text": "Fuzzing: 10,200 random programs, 1.3 million hashes, zero GPU to CPU mismatches on Apple silicon." }, + { "date": "2026-10-03", "text": "Second hostile review of the finality rule. Two fatal flaws found and fixed. Rule version 2 published in the design doc." }, + { "date": "2026-10-03", "text": "First prototype of the random-program lottery hash ran on an Apple M5 Max. GPU and CPU agreed bit for bit." }, + { "date": "2026-10-03", "text": "Igneum named. Litepaper, brand and wallet designs published." } + ] +} diff --git a/site/litepaper.html b/site/litepaper.html new file mode 100644 index 00000000..eb27c0e0 --- /dev/null +++ b/site/litepaper.html @@ -0,0 +1,453 @@ + + + + + + +Igneum Litepaper + + + + + + + +
+
+
+
+ + IGNEUM +
+ +
Litepaper · version 0.1
+

Mined by GPUs.
Proven by fire.

+
A proof-of-work chain whose miners also prove every block, run Ethereum's apps, and built so no chip can ever take your place.
+
+
+ Published 3 October 2026 + Coin IGN · cap 4,000,000,000 + Status pre-specification, pre-testnet + This is not an offer to sell anything +
+
+ +
+ + +
+
+

Abstract

+

Igneum is a proof-of-work blockchain mined on graphics cards, where the same cards prove every block with zero-knowledge proofs and sell proving to other chains.

+

It runs the Ethereum virtual machine, so anything built for Ethereum runs on Igneum unchanged. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two. There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining stays open to anyone with a GPU because the mining program itself changes every hour, so there is nothing for a specialised chip to be built for. Nothing in it ever needs a human to keep it that way.

+
+
1 / s
blocks at launch, rising to 10
+
~60 s
to a verified proof at launch
+
0
premine, pre-sale, allocation, stake
+
100%
of emission to miners and provers
+
+
+ +
+

What has never been done before

+

Every piece of Igneum has a precedent somewhere. The combination has none, and six of the pieces are firsts on their own.

+
+ + + + + + + + + +
FirstClosest precedentWhat Igneum adds
A mining program that regenerates itself, for GPUsRandomX does it for CPUs on Monero, since 2019The GPU version. Designed, discussed, never shipped
The mining card does paid, useful, verifiable workPrimecoin's prime chains in 2013 were not useful. Aleo's proving-as-consensus centralisedProving is useful, verifiable in milliseconds, and kept apart from the lottery
A proof-of-work chain where every block is provenzkEVMs exist only as rollups on top of proof-of-stake EthereumEthereum apps on a GPU-mined chain whose state cannot be wrong
Finality held by miners and immune to hour-long rentalsDecred votes with stake. Horizen penalises hidden chains. Kaspa limits depthSustained-mining weight: hashrate that appeared today has no vote
100% of emission to the people running the hardwareKaspa's fair launch, with no utility. Zcash and Decred fund developers from emissionFair launch, utility, and a development fund paid by outsiders and spent by miners
A chain your browser verifies by itselfLight clients trust a committeeOne proof plus one locked checkpoint, no trust
+
GPU mining lost its home in 2022. Igneum is the first chain built so that it can never be taken away again: not by a chip, not by a merge to proof of stake, not by a rental attack, and not by a foundation.
+
+ +
+

The problem

+

Three things are wrong at once, and Igneum is built where they meet.

+

GPU mining has no home

+

Ethereum left proof of work in 2022 and stranded the largest fleet of general-purpose compute ever assembled. Every chain that tried to take it in since has either been captured by specialised chips within two years, as Kaspa was, or has stayed too small to pay the power bill. Miners burn electricity on a lottery and are paid in inflation. When the price falls they switch off, and the chain's security goes with them.

+

Proving is centralised

+

Rollups, bridges and soon Ethereum itself need zero-knowledge proofs of every batch and every block. Today those proofs come from a few private GPU clusters run by the rollup teams or by a handful of proving companies. The work is a commodity, a proof is correct or it is not, and the cheapest correct proof should win. It does not, because the people with the cheapest GPUs are not in the market.

+

Small proof-of-work chains get attacked

+

When rental markets can hire more hashrate than a chain has for an hour, double-spends against exchanges are cheap. Ethereum Classic, Bitcoin Gold and Vertcoin were all hit this way. Every one of them let hashrate that appeared a minute ago rewrite history.

+

Igneum gives the GPU fleet paid, useful, verifiable work. It gives the proving market its cheapest supplier. And it makes the right to rewrite history something that must be earned over a month of public mining, not rented for an hour.

+
+ +
+

Igneum at a glance

+

Five layers. The lottery decides who makes blocks. Proving decides nothing about consensus, which is what keeps the fastest prover from owning the chain. The two are kept apart on purpose.

+
+ + + + + + + + 1. Mining lottery + A random GPU program picks who makes the next block + New program every hour, so only a GPU runs it well + + + + 2. BlockDAG ordering + Parallel blocks are ordered, about one block a second + A transaction is included in roughly one second + + + + 3. EVM execution + Blocks carry transactions only; the proof computes the state + Solidity, wallets and tooling work unchanged + + + + 4. Miners prove the block + Shards proven on consumer GPUs, aggregated into one proof + Lands within about a minute at launch, paid from gas + + + + 5. Sustained-mining finality + Miners lock a checkpoint every 30 s, weighted by 30-day history + Fresh rented hashrate has no vote; nothing outside the chain + + + + External proving jobs + Rollups and bridges pay Igneum + Same GPUs, same proof format + + winning blockordered blocksstate transitionsaggregated proof + +
Five layers plus the external proving market. A block flows down the column; outside demand feeds the same miners from the side.
+
+
+ +
+

Mining: a program that never holds still

+

Every GPU chain that promised ASIC resistance shipped a fixed algorithm, and a fixed algorithm gets a chip the moment the prize pays for one. Igneum does not have a fixed algorithm.

+

Each hour the chain derives a seed from a locked checkpoint one epoch back, passes it through a ten-minute verifiable delay so no miner can see which program a seed implies before choosing whether to publish a block, and feeds it to a deterministic generator. The generator emits a random integer program built from what graphics cards are uniquely good at: wide parallel integer maths, shuffles between the 32 lanes of a warp, and random reads over a multi-gigabyte dataset that changes daily, so the program is bound by memory bandwidth. The memory footprint and instruction count are fixed and only the maths sequence is random, so no hour favours one vendor's cards and nobody gains by grinding the seed. Miners compile the program once per hour. Anyone running a node, a wallet or an exchange checks a hash on an ordinary CPU in about ten milliseconds by simulating one warp, so nobody needs a GPU except to mine.

+
+ + + + + + + + +
ClockWhat changesMiner update needed?
Every hashThe data path depends on the nonce, so no two hashes run the same sequenceNo
Every hourA new random programNo, the miner compiles whatever arrives
Every dayA new datasetNo
Every six monthsA new instruction mix and memory pattern drawn by the chain from rules fixed at genesis, and a new family of instructions unlocked from a reserve written at genesis, so the program space widens every eraNo
ContinuouslyThe dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. A chip is built with fixed memory, so it is on a countdown from the day it ships. Ethereum's growing dataset killed Bitmain's E3 miner in 2020 this way, with nobody doing anythingNo
+

Everything above is automatic. Nobody writes a new program, nobody schedules a fork, and Igneum runs for ever on the generator fixed at genesis, exactly as Monero has run on RandomX since 2019 with no chip built. The generator is designed so that the best hardware for any program it can emit is a graphics card. A chip that dropped the graphics parts and kept the parallel cores and the memory would gain under 2x, approximate, which is below what pays for a tapeout, and that is the same margin that has protected Monero for seven years. On top of that, the widening program space and the growing dataset mean a chip designed for this year's Igneum meets a harder Igneum next year without anyone lifting a finger.

+

One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built so that day never comes, and it does not depend on it.

+
+ +
+

Monero's idea, finished for GPUs

+

RandomX has kept chips off Monero since 2019 by making the mining program random, so the only hardware that runs it well is the hardware everyone already owns. Igneum takes the same principle to graphics cards and adds what RandomX never had.

+
+ + + + + + + + + + + +
PropertyRandomX, MoneroIgneum
Hardware it is built forCPUs. GPUs run it badly on purposeGPUs. Any card, any vendor. Bit-exact on Apple and NVIDIA, measured
Random programPer hash, interpreted in a virtual machinePer hour, compiled to native GPU code, with a per-hash random data path
DatasetAbout 2 GB, the same size since 2019, approximate2 GB at genesis, growing every year past any chip's memory
Light verification256 MB cache on a CPU, milliseconds256 MB cache on a CPU, one warp under 10 ms, the measured gate
Changes over timeNone. A fixed design, unchanged for seven yearsAutomatic era draws and a reserve of instruction families that unlock by height. Nobody touches it
Seed grindingNot applicable, the program comes from the hash inputClosed by a verifiable delay between seed and program
Useful workNone. Hashing onlyThe same card proves every block and sells proofs to other chains
Track recordNo chip in seven yearsZero years. Every number above is measured, published, and reproducible from the repository
+

Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. AMD is the next test.

+
+ +
+

Proving: the miners are the provers

+

Every Igneum block is proven with a zero-knowledge proof, and the miners produce it. Proving is the one useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not, and a phone can check it in milliseconds.

+

How a block gets proven

+

Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Miners claim shards with a small bond, prove them on consumer cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch. Because the proof computes the state from the ordered sequence, a block with a wrong state cannot exist. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.

+

The proving budget

+

Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Shard size is set so a 12 GB card proves one shard in about 20 seconds, measured on a mid-range card before launch and raised by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface, so Igneum can adopt a better proof system when one exists by a miner-signalled release, and runs for ever on the current one if none is adopted.

+

Proving for everyone else

+

The same miners accept proving jobs from other chains. Rollups post a job, a miner wins it, proves it, and is paid. The job market is permissionless, the Igneum miner client also bids on other proving networks and takes the best price, and 10% of every job fee is burned. The proving market is small today. Igneum does not depend on it. No other proof-of-work chain has a seat in it.

+
+ +
+

Speed and finality, powered by miners alone

+

Speed

+

Igneum orders blocks with GHOSTDAG, the BlockDAG consensus proven on Kaspa. Blocks arrive in parallel and are ordered rather than orphaned, so the chain runs at one block a second at launch with scheduled steps to four and ten. A transaction is included in about one second, against twelve on Ethereum, and locked in about two minutes against roughly thirteen. Emission is paid per unit of difficulty-adjusted work, never per block, so a faster chain never means more coins.

+

Finality

+

Every 30 seconds of chain a checkpoint forms, deep enough past the tip that the DAG will not reorder it. Every miner with at least 100 blocks in the last 30 days signs it, and the checkpoint locks when signatures representing two thirds of the active mining weight arrive. A locked checkpoint overrides the heaviest chain, so no amount of fresh hashrate can reorganise past it.

+
The word sustained is the whole defence. Block rewards go to whoever mines, new or old. The right to lock history is earned.
+

A miner's vote weight is simply the blocks it has mined over the trailing 30 days, measured by work, so splitting into many keys buys nothing and joining a pool costs nothing. Hashrate that arrived today holds almost none of it. Even an attacker who brought the whole network's hashrate would need ten days of mining in public to hold a third of the weight, and twenty days to hold two thirds. At 51% of the network they never reach two thirds at all while the honest miners keep mining. Rental is priced by the hour. The only route left is to drive honest miners off the chain and hold two thirds for a month on the public hashrate charts, which is the same limit Bitcoin lives with, with a month's warning attached.

+

Two further rules close the gaps. Only miners who are present count: a key that stops signing drops out of the denominator within two hours, so a silent minority cannot freeze finality and a lock never waits for miners who have left. And Kaspa's one-hour merge-depth bound limits any reorganisation beneath the latest lock. Signing two different checkpoints at the same height is equivocation, provable by anyone, and it strips the key of its vote for 30 days.

+

What is not here

+

No stake. No coin-holder class votes on anything. No anchoring into Bitcoin or any other chain. Nothing in Igneum's consensus depends on anything outside Igneum.

+
+ +
+

Building on Igneum

+

Anything that runs on Ethereum runs on Igneum unchanged. Same Solidity, same bytecode, same wallets, same tools, a different chain id. Builders get Ethereum semantics with one-second inclusion, finality in about two minutes, and gas priced for a chain that is not congested.

+

Three things run on Igneum that run nowhere else.

+
    +
  1. Proving as a native primitive. A contract can request a proof of any computation and pay for it in gas, and the miners produce it. A game proves a fair shuffle. A lending market proves its solvency. A rollup elsewhere posts a job and gets its proof back. No other EVM chain has a prover network in its base layer.
  2. +
  3. Trustless light clients. Because every block is proven, a phone or a browser verifies Igneum's state by checking one proof and the latest locked checkpoint. Bridges built on that need no multisig, the piece that has failed in the biggest bridge hacks.
  4. +
  5. Rollups that settle here. A rollup posting to Igneum gets its proofs from the same miners that secure it, in the same flow. Settlement and proving in one place costs less than paying a proving network and a settlement layer separately.
  6. +
+

The first apps, a DEX, a lending market and an Ethereum bridge, ship at genesis so there is somewhere to use the coin from day one.

+

What a builder gets for being early

+
    +
  • Apps earn the gas they generate. 15% of every transaction's priority fee goes to the contracts whose code ran, by gas consumed inside each, paid every block to the developer address registered at deployment. Canto and Blast proved builders come for this. On Igneum it comes out of fees, never out of miner emission.
  • +
  • Stablecoins at genesis. USDC and USDT bridged through the proof bridge, canonical versions on Igneum, the way Arbitrum and Base launched. Native USDC is requested from Circle during public testnet. Igneum issues no stablecoin of its own.
  • +
  • Liquidity from the people who are there. The DEX is seeded by the founders' own mined coins and by miners, and every miner is a funded wallet from day one.
  • +
  • Launch grants. Paid from the founders' own mined coins, never from emission, to the first apps that bring users.
  • +
  • A minute of proof lag costs you nothing. Execution is immediate, the block is locked by miners in about two minutes, and the proof is a guarantee on top. A bridge withdrawal waits for the lock, about two minutes, against seven days on an optimistic rollup.
  • +
+
+ +
+

Economics

+

The coin is IGN. It is gas, it is the proving currency, and it is what every outside customer pays in. Part of every payment is burned.

+

Supply

+

Fair launch. No premine, no pre-sale, no allocation to anyone. Hard cap of 4 billion IGN, approached and never reached, because emission starts at 1 billion a year and halves every two years for ever. Nearly a quarter of all supply is mined in the first year and half in the first two, so the people who show up early get the most. Emission ramps from 10% to 100% over the first 30 days so that nobody takes the first month before the rest of the world hears about it.

+
+ + Half of the 4 billion cap is mined in the first two years + Millions of IGN issued per year, halving every two years for ever + + + + + + + + + + + + + 1000100050050025025012512563633131 + + + 123456789101112 + + Year after launch + +
Emission schedule, fixed in consensus. 3,938M IGN in the first 12 years of a 4,000M cap.
+
+

Where every coin of emission goes

+
+ + + + + + +
ShareGoes toWhy
80%The miner who wins the blockPays the hashrate that secures the chain
20%The proving pool: shard provers and aggregatorsPays a standing prover population that does not have to hash
0%Treasury, foundation, team or stakeThere is no coin-holder class in consensus and no tax on emission
+

Where the price comes from

+

The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits four ways: 65% to the miner and provers of that block, 15% to the apps whose code ran, by gas consumed inside each, 15% burned, 5% to the development fund. External proving fees burn 10%. The hard cap fixes supply. Demand comes from use of the chain and from outsiders buying proofs, and both reduce supply as they happen. Emission is untouched by any of this: every coin minted still goes to miners and provers.

+

Development, paid by outsiders and controlled by miners

+

5% of gas and 5% of external job fees go to a development fund held in a contract. Not one coin of emission goes to it, so miners are never taxed. Spending from it needs 60% of hashrate signalling yes over two weeks. Miners hold the purse. The users and rollups who want Igneum to keep improving fill it.

+
+ +
+

For miners

+

Igneum is built for the GPU fleet that has had no home since 2022. Here is what it offers and what it asks.

+

Three income streams, one balance

+
+ + + + + + +
StreamPaid byMoves with the IGN price?
Block rewardEmission, 80% to the winnerYes
In-chain provingThe 20% proving pool plus the proving share of every block's gasYes, mostly
External proving jobsRollups and apps on other chains, priced in their moneyNo, but the market is small today and is upside, not a promise
+

The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners have the lowest marginal cost in the proving market and are the last provers to switch off.

+

Hardware

+

The dataset starts at 2 GB and grows by half a gigabyte a year, so a 4 GB card mines for about four years and an 8 GB card for more than a decade, approximate. 12 GB or more proves full shards. NVIDIA and AMD both work, because the mining program is generated for the architecture both share and the proof system is hash-based. Apple's chips are GPUs with unified memory, so Macs mine too. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.

+

What a miner's hour looks like

+

The card hashes the lottery continuously. When the client sees a shard or an external job it can win, it switches the card to proving for a few seconds, posts the proof, and goes back to hashing. The client does the switching and the miner sees one balance. The official client is open source and charges a 1% dev fee, like every miner you already run, and any other client is welcome.

+

One click, for everyone else

+

Farm operators get HiveOS support on day one. Everyone else gets the Igneum app: install it on Windows, macOS or Linux, press one button, and the card is mining and proving to a wallet the app made for you, with earnings shown in IGN and in your currency, and mining paused while you game. It is the same client with a face on it. Mining never runs in a browser, because browser compute is slow and browser mining has meant malware since Coinhive. The browser is for the dashboard, and for verifying the chain.

+

Fair launch, announced

+

Launch date and miner software published a month ahead. Pools live on testnet. HiveOS support on day one. The founders mine from genesis like everyone else, with disclosed addresses and the same software. Nobody has coins before block one.

+
+ +
+

Governance

+

Igneum is governed by the people who power it, and by nobody else.

+
    +
  • Nothing needs a scheduled upgrade. The mining program, the dataset and the finality rules run themselves for ever. If the community ever ships an improvement, a better proof system or a block-rate step, it is published with test vectors at least three months ahead and activates only when 90% of blocks signal readiness. Developers can write code. Only miners can turn it on.
  • +
  • The development fund is spent by miners. Every proposal passes or fails on 60% of hashrate signalling over two weeks, and the fund is filled by fees, never by emission.
  • +
  • Pools cannot censor. Igneum uses Stratum v2 from day one, so each miner chooses its own transactions even inside a pool.
  • +
  • There are no admin keys. Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy.
  • +
  • The chain runs without its founders. Blocks, proofs and finality need no one. Upgrades need a second independent node client, funded from the development fund as its first priority.
  • +
+
+ +
+

Roadmap

+

Thirteen months from specification to a fair launch, with four public gates. Each gate is a measurement published whether it passes or fails. Miss it and the phase repeats or the project stops.

+
+ + + + + + + + + +
PhaseWhenWhatGate to pass
1. SpecificationOct to Nov 2026Mining generator, shard proving, finality rules, written for external review
2. Prove the provingNov 2026 to Jan 2027Mining program prototype on GPU and CPU, shard proving benchmark on consumer cardsA mid-range GPU proves a shard in under 20 s and a CPU verifies a hash in 10 ms
3. DevnetFeb to Mar 2027BlockDAG node with the new mining program and EVM execution, 20 nodes1 block a second held with proofs under 60 s behind the tip
4. Finality and job marketApr to Jul 2027Sustained-mining finality, external proving jobs, miner client with auto-switchingFinality design passes external review and one rollup signs for testnet
5. Public testnetAug to Oct 2027One-click miner app on Windows, macOS and Linux, HiveOS, pools, the first rollup as a proving customer, no coin yet1,000 independent miners run 30 days and rollup proofs are delivered on time
6. Mainnet fair launchNov 2027Genesis with no premine, 30-day ramp, exchange listings after
+

Phase two decides everything. If consumer GPUs cannot prove shards fast enough, Igneum says so and does not launch on promises.

+
+ +
+

Questions miners ask

+

Kaspa said ASIC resistant too, and IceRiver shipped a chip in eighteen months.

+

Kaspa's hash was one fixed function, simple enough to put on silicon. Igneum's program is different every hour, its dataset grows past any fixed memory, and its program space widens every era, with no human involved. In January 2027 the benchmark tool is public, so you run it on your own card and post the number to a leaderboard by card model. A standing bounty pays anyone who can show a chip design that beats a GPU by more than 2x. And if a chip ever appears, miners are the ones who signal the response.

+

Finality weighted by mining history is new. New gets attacked.

+

Correct, and it is the first thing the external review is paid to break. The specification is public, the review is gate 3 with named reviewers and a bounty, and the chain runs on plain GHOSTDAG without it, so the rule can be fixed without stopping the chain.

+

Who are you?

+

The founders mine from genesis with disclosed addresses and the same software as everyone else, and hold no coins before block one. The team page is published at public testnet, with the people, the mining addresses and the code history.

+

Where is the miner?

+

Benchmark in January 2027. Miner client with the devnet in spring. One-click app on Windows, macOS and Linux at public testnet in August 2027. All of it before any coin exists. Nothing is asked of a miner before they can run something.

+

Will my card still pay in a bear market?

+

Block reward and in-chain proving move with the price. Proving for other chains is priced in the customer's money, and it is a small market today. What Igneum can promise is that its miners have the lowest cost in that market, because the card is already running on domestic power, so they are the last to switch off. That is an edge and nothing more.

+
+ +
+

Questions builders ask

+

Proof of work, in 2027?

+

Igneum's miners are paid for proving, not only for hashing, so the energy buys a proof of every block as well as the ordering of it. Proof of work also gives what stake cannot: no stake to capture, no builder cartel between you and the block, no foundation that can change the rules, and a chain whose state is proven at the base layer, which Ethereum does not have today.

+

What does a one-minute proof mean for my app?

+

Nothing you wait for. Your transaction executes in about a second. A miner lock arrives in about two minutes and that is the finality your contract sees. The proof follows and makes the state unforgeable. Liquidations and trades act on executed state at once, as on any chain. Bridge withdrawals wait for the lock, about two minutes.

+

Which stablecoin, and is there liquidity?

+

USDC and USDT, bridged through the proof bridge at genesis as the canonical versions on Igneum. Native USDC is requested from Circle during testnet. The DEX is seeded at launch by the founders' own mined coins and by miners, and every miner is a funded wallet.

+

What do I get for being early?

+

15% of the priority fee on every transaction that runs your code, paid to you every block. Launch grants from the founders' mined coins. A place in the wallet's Apps tab and the explorer from day one. And the only user base a new chain has ever had that did not have to be paid to arrive.

+

How do I deploy?

+

Point Hardhat or Foundry at an Igneum node with the chain id and deploy the same bytecode. Verify the source in the explorer. Register a developer address for the gas share. The afternoon is the hard part.

+
+ +
+

What Igneum does not claim

+

Here are the limits, stated before anyone else states them.

+
    +
  • A proof in seconds. Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.
  • +
  • A chip is impossible. No. A chip is pointless, because the target moves before it ships. The honest efficiency ceiling for a fixed chip on a memory-bound program is under 2x, approximate, and Igneum's generator changes under it every hour.
  • +
  • A guaranteed income floor. No. External proving is a small market today. Igneum's miners have the lowest cost in it, which is an edge and nothing more.
  • +
  • Finality that no amount of hardware can break. No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded to one hour. Reaching a third takes at least ten days of the whole network's hashrate, in public. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose.
  • +
  • A finished protocol. The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.
  • +
+

Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything.

+
+
+
+ + +
+ + + diff --git a/site/vercel.json b/site/vercel.json new file mode 100644 index 00000000..63228c38 --- /dev/null +++ b/site/vercel.json @@ -0,0 +1,13 @@ +{ + "cleanUrls": true, + "trailingSlash": false, + "headers": [ + { "source": "/(.*)", "headers": [ + { "key": "X-Content-Type-Options", "value": "nosniff" }, + { "key": "X-Frame-Options", "value": "DENY" }, + { "key": "Referrer-Policy", "value": "strict-origin-when-cross-origin" }, + { "key": "Strict-Transport-Security", "value": "max-age=63072000; includeSubDomains; preload" } + ] }, + { "source": "/journey.json", "headers": [ { "key": "Cache-Control", "value": "public, max-age=300" } ] } + ] +}