diff --git a/docs/analysis/chip-model-v3.md b/docs/analysis/chip-model-v3.md index e98ed5e42..0fdfcdbb3 100644 --- a/docs/analysis/chip-model-v3.md +++ b/docs/analysis/chip-model-v3.md @@ -357,6 +357,12 @@ Reading: NO. Class v5 with the shadow at zero leaves the strongest chip at 5.1x Per tier: a miner on class v4 pays the premium and gets the 2.1x to 3.9x chip ceiling in exchange; on class v5 with the shadow kept the ceiling stays and the dataset is the chain's; on class v5 with the shadow dropped the premium goes and the ceiling returns to 5x to 9x. The decision is the founder's; this section gives the number. +### 5.11 Two columns from the counter-asic-4 research file (7 October 2026, 22:3x UK; `docs/analysis/counter-asic-4-research.md` sections 15 to 19 at bca23f96, the research lane's reading, carried here as the chip model's own columns) + +The k column. k is the chip core's energy per op over the GPU's at the same operating point, and the model's 3.4x row takes k about 0.33 for an ALU-shaped core. On the public figures the int8 tensor tile is the one GPU block whose energy per op a chip at the same node cannot undercut with certainty: the 4090 measures 0.056 pJ per MAC; NVIDIA's 5 nm INT4 test chip reads 0.021 pJ per MAC at 0.46 V and about 0.1 at nominal (JSSC 2023, via Dally's NASEM slides; claimed), so INT8 at 2x to 4x that gives k 0.7 to 3 with the centre near 1; every ALU-shaped block reads k 0.3 to 0.8 on the same sources. A shadow built of tensor tiles at the ALU shadow's premium (about 11,400 u8 tiles per hash) therefore gives 2.1x at k = 1 and 1.6x at k = 1.5 and removes the k 0.3 column from the table; it needs a SIMD byte-dot verifier (the scalar one at 12.4 ms fails the 10 ms gate). This is a design candidate, not the shipped stream: the shipped shadow is ALU-shaped and its row stays 2.1x at k = 1 and 3.4x at k about 0.33. + +The capex column. The `f = 1` GDDR7 chip of 5.5 is USD 2.8 per MH/s of silicon and memory, which is USD 0.00016 per MH/s-hour of capex over two years against USD 0.000023 of electricity: capex-dominated 7x, as the 5090 is (USD 14.7 per MH/s at MSRP, 10x). A 64 MiB hot table adds about USD 15 of N5 die, the shadow core USD 25 to 40, an interposer USD 200, so the chip's capex reaches at most about USD 4.3 per MH/s: the per-unit capex wall is unreachable by 3x to 7x, and the break-even market cap moves only through the project cost (the mission lane's model: about USD 100 M with the N5 shadow core, about 200 M if the shadow runs per load and forces one die or an interposer). Every figure here is modelled on cited or claimed parts; the research lane's microbench (20 probes, the mma_u8 and l2 rows the ones this model would take) is on PC 1's queue after the hot-table job. + ## 6. The per-day derivation (item 2) 6 October 2026, Counter ASIC 3.0 item 2, worker `derive` (`docs/plans/counter-asic-3-derivation.md`; everything diff --git a/docs/evidence.md b/docs/evidence.md index 4910bd485..07b80e10b 100644 --- a/docs/evidence.md +++ b/docs/evidence.md @@ -41,7 +41,7 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml` | 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13; fixes `F-exec-A`, `F-exec-B` (spec 7.5) | `tools/evm-smoke/smoke.mjs`: deploy via viem, `increment`, `hashLoop`, `eth_estimateGas`, `eth_getLogs`; `tools/exec-attacks` scenarios 1 and 3; bench-log "execution layer attack fixes" | Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The `Prover` precompile, proof records and the shard planner are not in the node | none yet | | 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | implemented | repo `d7e1f89` (GPU proof), `e01a3cc`, `292e800`, `eedd136` (`proving/igneum-prove`: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6 | `proving/windows-wsl2` (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; `igneum-prove-host --mode block` on `proving/fixtures/`; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards" | First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture `block-78-increment` (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in `docs/benchmarks/proving-e2e.md`. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Mac in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind `proving_v1_activation_daa` (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one | none yet | | 16 | A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves) | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target), 7.6 (`S_p` provisional, 7,500,000 pgas = `B_p` / 4) | `PROVE-SHARD.bat` on the RTX 5090 (pending); the end-to-end standard in `docs/benchmarks/proving-e2e.md`; bench-log "proving: devnet v4 shards" | Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional `S_p` is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card | none yet | -| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026). | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | +| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026). | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and no outside review has run yet | | 18 | The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache | Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page | tested by the team | readwidth e752fc7 (`docs/plans/read-width.md`), ca2-era 78c0ee4, ca2-cache 2de19e5 (`docs/plans/hot-table.md`) | The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load | Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026 | none yet | | 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors | Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page | tested by the team | ca2-mixer 1ab8b21 (`tests/mixer.rs`, `tests/scratch.rs`), ca2-era 78c0ee4, ca2-soundness a465881 (`docs/analysis/scratch-soundness.md`), `igneum-pow/tests/packs.rs` | The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card | Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing) | none yet | | 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo `6ac80a3`; fork "igneum-node devnet v0"; `consensus/core/src/igneum.rs`, `coinbase.rs` | `cargo test -p kaspa-consensus-core igneum` (8 pass: subsidy table, ramp, split, cap) and `cargo test -p kaspa-consensus coinbase` (8 pass); `igneum-miner inspect 40`; bench-log "igneum-node devnet v0" | Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the `igneum-proving-pool-v0` output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened | none yet | diff --git a/docs/plans/counter-asic-3-public-text-2026-10-07.md b/docs/plans/counter-asic-3-public-text-2026-10-07.md index ee0afaded..583a12c57 100644 --- a/docs/plans/counter-asic-3-public-text-2026-10-07.md +++ b/docs/plans/counter-asic-3-public-text-2026-10-07.md @@ -20,7 +20,7 @@ The chip model. We price the strongest chip we can design against an RTX 5090 an | When a stored-dataset chip pays for itself | at about USD 100 M of market cap in the first two years, not before | modelled, 7 October 2026 | | The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class) | 5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x) | modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state | -What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word. +What a miner sees from this. Class v4 costs a 5090 about 80 W more for 0.2 percent of rate, an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (all measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). On the devnet, which started on class v3, class v4 arrives by miner signal at a published height (a devnet fact, not a launch one). The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet. ## 3. The miner page's line @@ -30,4 +30,4 @@ Your card against the strongest chip we can price: an RTX 5090 at 136 MH/s on 35 | # | Claim | Where it is made | Status | Version or commit | Reproducible test | Result, date, machine | Independent verification | |---|---|---|---|---|---|---|---| -| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word | +| 17 | The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state) | the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line | tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measured | `docs/analysis/chip-model-v3.md` 5 and 6; `docs/analysis/latency-shadow-2026-10-06.md`; `docs/plans/counter-asic-3-status.md`; `docs/analysis/attack-pass/f8-uniform.md`, `f4-weakday.md`, `docs/analysis/ca3-v4-uniform.md`; `docs/design/class-v5-stored-state.md`; the H100 and market-cap rows of 7 October; `docs/plans/cryptanalysis/in-house-pass.md` (the internal adversarial pass) | the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses `tools/attack/f8-uniform` and the F4 census; the verifier by `igneum-pow bench` | 136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, PC 2's RTX 5090, PC 1's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 | none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and no outside review has run yet | diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index 48a1c0d6a..35c6a8a84 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -465,7 +465,7 @@ Reading: the class v4 premium is 145.3 W at the unlocked clock (not the 80 W of | 1,200 | 133.80 | 305.1 | 0.439 | 129.54 | 215.7 | 0.601 | 1,192 | | 1,100 | 122.43 | 287.3 | 0.426 | 118.70 | 209.4 | 0.567 | 1,087 | -The knee by main's rule (more than 1 percent lost against unlocked): 1,300 MHz on both classes (the rate within 1.5 percent of unlocked down to it; v3 falls 5.1 percent at 1,200, v4 10.5 percent at 1,100); the best MH per watt one step past it: v4 at 1,200 MHz (133.80 MH/s, 305.1 W, 0.439 MH/W, 168.6 W recovered for 2.2 percent of rate), v3 at 1,300 (134.62, 223.3 W, 0.603, 106.6 W for 1.4 percent). The v4 premium 143.8 W unlocked, 81.8 W at the best points; the v4 rate 0.25 percent over v3 unlocked and 0.61 percent under at the best points; the residual at the floor is the shadow's ALU work, not the clock. Per tier: a 5090 owner on class v4 locked at 1,200 to 1,300 MHz draws 305 to 313 W instead of 474 for 1.5 to 2.2 percent less rate, MH per watt up 49 to 52 percent; the Ember knob (0.3.24, the hash lane on the engine side, the UI lane's drawing) carries these as its reference rows. A FAULT FOUND AND FIXED: the steps 1,000 down to 300 and the closing reset got no answer from the Power Helper and the card sat at the 1,100 lock for about five minutes after the job (118 to 122 MH/s live); the installed app's own Ember tune on the 5080 wrote the same cmd.txt with higher sequence numbers while the script wrote lower ones, and the helper skips any sequence at or under the last run; the restore job run-ca3-pc1-clocks-restore-20261007 (exit 0 at 20:45:58Z) put the 5090 back at 2,865 MHz; the fix 45f9497f on the mirror (the sequence base from helper.log and cmd.txt, re-based after a timeout, an unanswered lock stops the grid, the task restarted before every reset); the rule for the knob: it takes its sequences from the engine's counter and no script shares the file with a running tune. The driver's floor below 1,100 is unmeasured. THE PC 1 QUEUE after the shipper's 0.3.23 host job (main, 21:5x UK): the 5080 full grid with the fix; the research lane's SM-sparse kernel job (the hash on a fraction of the SMs, several chains per thread, the rest clock-gated; the research lane hands the kernel to the hash lane); the third 5090 pass from 1,100 down to the driver's floor at the tail; then the 9070 XT G1 and ladder, the v5 AMD bench, item 6 on AMD, the 5080 and 9070 XT tunes, the L2 cache-policy hot table; each exit line to the shipper and the coordinator; the honest site sentence (the premium at the knee and the floor it buys, labelled measured, the Ember knob named as how a user gets there) once the 5080 reads. THE DERIVATION FINDING FIXED (the hash lane, 15008aca and 0f45c8be on the mirror): one byte recipe (generator::IdRecipe) builds the id and the printed text; program.json states the generator 4 suffix and the rung form; spec 1.4.6 corrected (class v5 = generator 5, no suffix); tests/derivation.rs re-derives all 18 pinned packs from their own text (the plain text gives 8aa9f185d63f269e for the devnet v4 pack, the known-failed case); 38 packs' program.json re-exported with ids, kernels and fingerprints byte-identical; the full igneum-pow suite green on box 2. CLASS V5 FROZEN: class-v5 1c420786 on both box mirrors at 21:53 UK (the (c''') floor with its number; section 14 with seven of seven live hot sets refused at 0.9821 to 0.9919, seed 170 at 0.9880 the seventh, and the three mild residuals at 0.9992 to 0.9997 named at about 1.0004x; the pinned pack unchanged; the flip-stale harness PASS on the matched binaries at 21:03 UK; the AP-F4-1 first form and the AP-F1-1 shadow rule, the latter's measured trigger 11 permille maximum over 6,000 first draws against the 30 bound, 0 redraws; the igneum-pow suite green on box 2: 73 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7; the gate GREEN at 58 checks). The kits lane: the 0.3.24 kit is packs-ca3-v5-20261007T183921Z.zip sha256 e6c088bb34fecdc3ff297dbb06438a14ade7d8c55273357726d28f7a1334a25e, byte-identical to the frozen 1c420786 (state.igsd1 included), fingerprint 82b19cbde8557ea5 on Metal, Apple OpenCL and a CUDA 4090; AMD on PC 1's queue, Intel deferred; the shipper has the line. The attack-pass lane runs F8 at 2^24, F9 at 10^5 and F1 on 1c420786 under class v5. The v5 lane's next commit on the freeze: AP-F4-1 in the agreed form (cost at most 205 against the median 226, w32 without the position-32 digit, k >= 1 and all-ROT-equal rejected, the known-failed day 29,337 = 2050-04-28) and the verified last resort (part (a) repaired by re-sourcing stale loads, then the whole rule over a 256-candidate scan, known-failed first on adv-accept-3's adv3/steer/2); both move the stream only on days and seeds the chain never reaches. THE FOURTH EXCEPTION ON THE RESTART STEP (the fast-time lane's held-miner run on the third pair 63524e28, 20:4xZ): the IBD catch-up's body sync anchored on the node's own sink and moved only on a whole chunk's successful join, so with the honest headers arriving as one chunk failing on its v5 tail it fetched nothing and the executor never reached the seed block; the relay hold-off and the mining hold from the earlier fixes read green on that run. FIXED by the node lane at f0c56f50 (the refused chunk split by consensus's own record, the anchor moved to the highest validated header, the honest v4 prefix through the seed block, only the unvalidated headers deferred; kaspa-p2p-flows 38). PAIR 4 = v5-object-0323 c8f9b383, re-archived from the frozen 1c420786 (generator.rs and accept.rs moved since ab6f980b, memhard.rs not), building on build-1 at gate priority since 20:54:32Z with the line's gates beside it; the restart step's PASS must come from pair 4; the object commit lands the minute it does, with dn3-g1's DAA at the cut plus 7,200 rounded up to the 3,600 boundary and its UTC clock named; the testnet lane told to pair its re-cut with 1c420786. The crossing clock is not yet a reading: about 22:15Z (23:15 BST) at the earliest if every line reads green on its first pass. The site audit lane: no other "12 days" form served; its row-17 edit keeps main's outside-check clause and adds the 5090 efficiency numbers. THE CHIP TEXTS, THE X9 WORDING RETIRED (main's order from the counter-asic-4 research file d7721ebe, 22:0x UK): the withdrawn Antminer X9's claimed ratio ("a third of a CPU's energy per RandomX hash") is against a CPU core (about 100 pJ per instruction, Horowitz and Dally, claimed), not a GPU lane (6.5 to 10.4 pJ measured), so a chip three times better than a CPU is worse than a GPU lane per op and the X9 is not a pessimistic chip core against us. The served texts (the home line, the litepaper's lead, chip table, ladder sentence and chip bullet, /claims through it, the miner line, evidence row 17) now give the floor and the premium as measured numbers at the 5090's knee: the chip at 2.1x per joule with a core as good as a GPU lane (k = 1) and 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op in the model's range, the shadow's premium 81.8 W at the best points (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W against class v3 at 1,300 MHz 134.62 at 223.3 W, 7 October 2026), Ember Tune's core-clock knob named as how a user gets there; the ledger text check's pins X35 and X36 moved with the wording; no "3.9x" remains on any served page. One number stated against main's wording: main's line read "2.9x with one three times better", which in the research file is the figure for the RE-WEIGHTED op mix (row 3, held by the coordinator until the SM-sparse read); today's mix at a core three times better reads 3.4x in the same file, so the served text carries 3.4x and the 2.9x waits for the re-weight to ship. THE RESEARCH FILE's TWO ORDERS: (1) the texts as above; (2) one zero-code measurement at the PC 1 tail after the third 5090 pass: the 5 October hot-table packs (packs-ca2-hot, 32 and 64 MiB) with the worker's `--variant ldcs` (dataset loads streaming, evict-first; the hot loads plain and L2-resident) against base on the 5090, the rate ratio g and the watts (the 5 October rows without the hint g 0.84 to 0.87); the one class where a chip's cost per op (a 64 MiB SRAM read, 0.2 to 0.5 nJ approximate) may exceed the GPU's (an L2 hit, 0.1 to 0.3 nJ); Metal has no such hint. The shadow stays at rung 0; the op-mix re-weight waits for the SM-sparse read (the research lane's worker variants sp170/85/43/21/11-w32, one block of 32 warps per SM, run through the hash lane's efficiency script in its ca4 mode at 4f3a064e; the no-prompt and sequence rules hold by the same code). THE 0.3.24 PAIRING RULED (the shipper, 22:1x UK): the v5 object commit pairs with the frozen class-v5 1c420786 as it stands (the gates and the attack-pass lines run on it); the post-freeze fix 8ca66afa is 0.3.25's pairing. 0.3.25's FIRST ROW: class-v5 8ca66afa (both mirrors, 22:10 UK, on 1c420786): (1) AP-F4-1 in the agreed form (decc7c17): the day's draw rejected when cost A = 64 + sum(w32(MUL_i) - 1) is at most 205 against the median 226, w32 over bit positions 0 to 31 (the position-32 carry digit dropped), any MUL with w32 at most 3 rejected (k >= 1), the eight ROT all equal rejected, a rejected block redrawn whole from the continuing stream; known-failed first on chain day 29,337 (2050-04-28): the sub-version 3 block of that day read cost 203, rejected at 205 and redrawn under class v5. (2) Class v5's verified last resort: the rewrite, then repair_stale_loads (a stale load re-sourced to the lowest register written since its last load, to a fixpoint), then the whole rule over a 256-candidate scan from the cap; the unchecked fallback past the scan under 1e-300; known-failed first on adv-accept-3's adv3/steer/2 (the sub-version 3 rewrite fails part (a) at instruction 47 reading r3; the repair restores (a) moving only load sources; class v5's last resort passes at attempt 256, id 9b29c9481f6941d4; steer 11, 33, 56, 58 and 77 pass too); sub-version 3's path untouched. The stream moves only on days and seeds the chain never reaches: the pinned v5 packs byte-identical, the fingerprint 82b19cbde8557ea5 and the epoch-0 id e5a4ac5978462156 unchanged; the igneum-pow suite green on box 2 (74 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7), the gate GREEN at 58 checks. The harness's class-walk case (v4 floor 0, v3 never) read FAIL on the unfixed fork 546fe4b5 (the known-failed shape, 22:08 UK) and runs on pair 4. THE IN-HOUSE PASS, THE EIGHTH HOT SET (adv-accept, 22:06 BST, the wider sweep over 88,051 accepted programs): seed 122960 (id 4be7393ab6c84802, the lowest 256-unit ratio at 0.9885) reads live at 2^24 X_f +0.111 percent, X/f 1.11, 1.54x the window model, with the heaviest single item measured tonight (0x81ad88 at 475,616 reads, 0.022 percent of all reads, 16x 100767's hottest) from an all-ones source at instruction 4 (writer shfl at 3); site 12's saturated-source share 0.353 percent, a third of (c')'s limit; the other four lowest 256-unit proxies clean live, so the 256-unit proxy is noise at its own extreme and the 2^20 ratio is the selector; the tally 8 hot sets in 30 tail seeds against 0 in 20 random; the price unchanged (0.34 percent of reads on 1 MB, 1.002x); its minimum-site ratio at 2^20 against the 0.995 floor OWED (ordered first), deciding whether the freeze record reads eight of eight refused or names the first hot set the floor misses. THE 5080 AT STOCK (run-ca3-pc1-v4-eff-5080-20261007-b, exit 0 at 21:03:02Z, the card alone, 60 s, both fingerprints matched): class v4 71.43 MH/s at 255.1 W (0.280 MH/W, sm 2,958, mem 14,801 MHz); class v3 71.30 at 170.7 W (0.418); the v4 premium 84.4 W (49 percent over v3's draw), the rate 0.18 percent over v3; against the fleet's rented 5080 (71.16 MH/s at 143.4 W on class v4, driver 580) the rate agrees to 0.4 percent and the watts do not (255 against 143), a question to the fleet lane (its sampler, a cap on the rented card, the memory clock) before either row enters the public table; the lock grid did not run in -b (a PowerShell function defined below its first call left the script without the helper path; nothing set, nothing to restore), republished as -c at 21:07:10Z with the full grid (unlocked to 300 MHz, about 58 minutes). The site audit lane's row 17 and litepaper paragraph carry the 1,400 MHz rows labelled measured, with the best-points clause asked beside the 88 W at 1,400. A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | +The knee by main's rule (more than 1 percent lost against unlocked): 1,300 MHz on both classes (the rate within 1.5 percent of unlocked down to it; v3 falls 5.1 percent at 1,200, v4 10.5 percent at 1,100); the best MH per watt one step past it: v4 at 1,200 MHz (133.80 MH/s, 305.1 W, 0.439 MH/W, 168.6 W recovered for 2.2 percent of rate), v3 at 1,300 (134.62, 223.3 W, 0.603, 106.6 W for 1.4 percent). The v4 premium 143.8 W unlocked, 81.8 W at the best points; the v4 rate 0.25 percent over v3 unlocked and 0.61 percent under at the best points; the residual at the floor is the shadow's ALU work, not the clock. Per tier: a 5090 owner on class v4 locked at 1,200 to 1,300 MHz draws 305 to 313 W instead of 474 for 1.5 to 2.2 percent less rate, MH per watt up 49 to 52 percent; the Ember knob (0.3.24, the hash lane on the engine side, the UI lane's drawing) carries these as its reference rows. A FAULT FOUND AND FIXED: the steps 1,000 down to 300 and the closing reset got no answer from the Power Helper and the card sat at the 1,100 lock for about five minutes after the job (118 to 122 MH/s live); the installed app's own Ember tune on the 5080 wrote the same cmd.txt with higher sequence numbers while the script wrote lower ones, and the helper skips any sequence at or under the last run; the restore job run-ca3-pc1-clocks-restore-20261007 (exit 0 at 20:45:58Z) put the 5090 back at 2,865 MHz; the fix 45f9497f on the mirror (the sequence base from helper.log and cmd.txt, re-based after a timeout, an unanswered lock stops the grid, the task restarted before every reset); the rule for the knob: it takes its sequences from the engine's counter and no script shares the file with a running tune. The driver's floor below 1,100 is unmeasured. THE PC 1 QUEUE after the shipper's 0.3.23 host job (main, 21:5x UK): the 5080 full grid with the fix; the research lane's SM-sparse kernel job (the hash on a fraction of the SMs, several chains per thread, the rest clock-gated; the research lane hands the kernel to the hash lane); the third 5090 pass from 1,100 down to the driver's floor at the tail; then the 9070 XT G1 and ladder, the v5 AMD bench, item 6 on AMD, the 5080 and 9070 XT tunes, the L2 cache-policy hot table; each exit line to the shipper and the coordinator; the honest site sentence (the premium at the knee and the floor it buys, labelled measured, the Ember knob named as how a user gets there) once the 5080 reads. THE DERIVATION FINDING FIXED (the hash lane, 15008aca and 0f45c8be on the mirror): one byte recipe (generator::IdRecipe) builds the id and the printed text; program.json states the generator 4 suffix and the rung form; spec 1.4.6 corrected (class v5 = generator 5, no suffix); tests/derivation.rs re-derives all 18 pinned packs from their own text (the plain text gives 8aa9f185d63f269e for the devnet v4 pack, the known-failed case); 38 packs' program.json re-exported with ids, kernels and fingerprints byte-identical; the full igneum-pow suite green on box 2. CLASS V5 FROZEN: class-v5 1c420786 on both box mirrors at 21:53 UK (the (c''') floor with its number; section 14 with seven of seven live hot sets refused at 0.9821 to 0.9919, seed 170 at 0.9880 the seventh, and the three mild residuals at 0.9992 to 0.9997 named at about 1.0004x; the pinned pack unchanged; the flip-stale harness PASS on the matched binaries at 21:03 UK; the AP-F4-1 first form and the AP-F1-1 shadow rule, the latter's measured trigger 11 permille maximum over 6,000 first draws against the 30 bound, 0 redraws; the igneum-pow suite green on box 2: 73 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7; the gate GREEN at 58 checks). The kits lane: the 0.3.24 kit is packs-ca3-v5-20261007T183921Z.zip sha256 e6c088bb34fecdc3ff297dbb06438a14ade7d8c55273357726d28f7a1334a25e, byte-identical to the frozen 1c420786 (state.igsd1 included), fingerprint 82b19cbde8557ea5 on Metal, Apple OpenCL and a CUDA 4090; AMD on PC 1's queue, Intel deferred; the shipper has the line. The attack-pass lane runs F8 at 2^24, F9 at 10^5 and F1 on 1c420786 under class v5. The v5 lane's next commit on the freeze: AP-F4-1 in the agreed form (cost at most 205 against the median 226, w32 without the position-32 digit, k >= 1 and all-ROT-equal rejected, the known-failed day 29,337 = 2050-04-28) and the verified last resort (part (a) repaired by re-sourcing stale loads, then the whole rule over a 256-candidate scan, known-failed first on adv-accept-3's adv3/steer/2); both move the stream only on days and seeds the chain never reaches. THE FOURTH EXCEPTION ON THE RESTART STEP (the fast-time lane's held-miner run on the third pair 63524e28, 20:4xZ): the IBD catch-up's body sync anchored on the node's own sink and moved only on a whole chunk's successful join, so with the honest headers arriving as one chunk failing on its v5 tail it fetched nothing and the executor never reached the seed block; the relay hold-off and the mining hold from the earlier fixes read green on that run. FIXED by the node lane at f0c56f50 (the refused chunk split by consensus's own record, the anchor moved to the highest validated header, the honest v4 prefix through the seed block, only the unvalidated headers deferred; kaspa-p2p-flows 38). PAIR 4 = v5-object-0323 c8f9b383, re-archived from the frozen 1c420786 (generator.rs and accept.rs moved since ab6f980b, memhard.rs not), building on build-1 at gate priority since 20:54:32Z with the line's gates beside it; the restart step's PASS must come from pair 4; the object commit lands the minute it does, with dn3-g1's DAA at the cut plus 7,200 rounded up to the 3,600 boundary and its UTC clock named; the testnet lane told to pair its re-cut with 1c420786. The crossing clock is not yet a reading: about 22:15Z (23:15 BST) at the earliest if every line reads green on its first pass. The site audit lane: no other "12 days" form served; its row-17 edit keeps main's outside-check clause and adds the 5090 efficiency numbers. THE CHIP TEXTS, THE X9 WORDING RETIRED (main's order from the counter-asic-4 research file d7721ebe, 22:0x UK): the withdrawn Antminer X9's claimed ratio ("a third of a CPU's energy per RandomX hash") is against a CPU core (about 100 pJ per instruction, Horowitz and Dally, claimed), not a GPU lane (6.5 to 10.4 pJ measured), so a chip three times better than a CPU is worse than a GPU lane per op and the X9 is not a pessimistic chip core against us. The served texts (the home line, the litepaper's lead, chip table, ladder sentence and chip bullet, /claims through it, the miner line, evidence row 17) now give the floor and the premium as measured numbers at the 5090's knee: the chip at 2.1x per joule with a core as good as a GPU lane (k = 1) and 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op in the model's range, the shadow's premium 81.8 W at the best points (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W against class v3 at 1,300 MHz 134.62 at 223.3 W, 7 October 2026), Ember Tune's core-clock knob named as how a user gets there; the ledger text check's pins X35 and X36 moved with the wording; no "3.9x" remains on any served page. One number stated against main's wording: main's line read "2.9x with one three times better", which in the research file is the figure for the RE-WEIGHTED op mix (row 3, held by the coordinator until the SM-sparse read); today's mix at a core three times better reads 3.4x in the same file, so the served text carries 3.4x and the 2.9x waits for the re-weight to ship. THE RESEARCH FILE's TWO ORDERS: (1) the texts as above; (2) one zero-code measurement at the PC 1 tail after the third 5090 pass: the 5 October hot-table packs (packs-ca2-hot, 32 and 64 MiB) with the worker's `--variant ldcs` (dataset loads streaming, evict-first; the hot loads plain and L2-resident) against base on the 5090, the rate ratio g and the watts (the 5 October rows without the hint g 0.84 to 0.87); the one class where a chip's cost per op (a 64 MiB SRAM read, 0.2 to 0.5 nJ approximate) may exceed the GPU's (an L2 hit, 0.1 to 0.3 nJ); Metal has no such hint. The shadow stays at rung 0; the op-mix re-weight waits for the SM-sparse read (the research lane's worker variants sp170/85/43/21/11-w32, one block of 32 warps per SM, run through the hash lane's efficiency script in its ca4 mode at 4f3a064e; the no-prompt and sequence rules hold by the same code). THE 0.3.24 PAIRING RULED (the shipper, 22:1x UK): the v5 object commit pairs with the frozen class-v5 1c420786 as it stands (the gates and the attack-pass lines run on it); the post-freeze fix 8ca66afa is 0.3.25's pairing. 0.3.25's FIRST ROW: class-v5 8ca66afa (both mirrors, 22:10 UK, on 1c420786): (1) AP-F4-1 in the agreed form (decc7c17): the day's draw rejected when cost A = 64 + sum(w32(MUL_i) - 1) is at most 205 against the median 226, w32 over bit positions 0 to 31 (the position-32 carry digit dropped), any MUL with w32 at most 3 rejected (k >= 1), the eight ROT all equal rejected, a rejected block redrawn whole from the continuing stream; known-failed first on chain day 29,337 (2050-04-28): the sub-version 3 block of that day read cost 203, rejected at 205 and redrawn under class v5. (2) Class v5's verified last resort: the rewrite, then repair_stale_loads (a stale load re-sourced to the lowest register written since its last load, to a fixpoint), then the whole rule over a 256-candidate scan from the cap; the unchecked fallback past the scan under 1e-300; known-failed first on adv-accept-3's adv3/steer/2 (the sub-version 3 rewrite fails part (a) at instruction 47 reading r3; the repair restores (a) moving only load sources; class v5's last resort passes at attempt 256, id 9b29c9481f6941d4; steer 11, 33, 56, 58 and 77 pass too); sub-version 3's path untouched. The stream moves only on days and seeds the chain never reaches: the pinned v5 packs byte-identical, the fingerprint 82b19cbde8557ea5 and the epoch-0 id e5a4ac5978462156 unchanged; the igneum-pow suite green on box 2 (74 unit, packs 20, derive 7, mixer 4, recheck 2, scratch 7), the gate GREEN at 58 checks. The harness's class-walk case (v4 floor 0, v3 never) read FAIL on the unfixed fork 546fe4b5 (the known-failed shape, 22:08 UK) and runs on pair 4. THE IN-HOUSE PASS, THE EIGHTH HOT SET (adv-accept, 22:06 BST, the wider sweep over 88,051 accepted programs): seed 122960 (id 4be7393ab6c84802, the lowest 256-unit ratio at 0.9885) reads live at 2^24 X_f +0.111 percent, X/f 1.11, 1.54x the window model, with the heaviest single item measured tonight (0x81ad88 at 475,616 reads, 0.022 percent of all reads, 16x 100767's hottest) from an all-ones source at instruction 4 (writer shfl at 3); site 12's saturated-source share 0.353 percent, a third of (c')'s limit; the other four lowest 256-unit proxies clean live, so the 256-unit proxy is noise at its own extreme and the 2^20 ratio is the selector; the tally 8 hot sets in 30 tail seeds against 0 in 20 random; the price unchanged (0.34 percent of reads on 1 MB, 1.002x); its minimum-site ratio at 2^20 against the 0.995 floor OWED (ordered first), deciding whether the freeze record reads eight of eight refused or names the first hot set the floor misses. THE 5080 AT STOCK (run-ca3-pc1-v4-eff-5080-20261007-b, exit 0 at 21:03:02Z, the card alone, 60 s, both fingerprints matched): class v4 71.43 MH/s at 255.1 W (0.280 MH/W, sm 2,958, mem 14,801 MHz); class v3 71.30 at 170.7 W (0.418); the v4 premium 84.4 W (49 percent over v3's draw), the rate 0.18 percent over v3; against the fleet's rented 5080 (71.16 MH/s at 143.4 W on class v4, driver 580) the rate agrees to 0.4 percent and the watts do not (255 against 143), a question to the fleet lane (its sampler, a cap on the rented card, the memory clock) before either row enters the public table; the lock grid did not run in -b (a PowerShell function defined below its first call left the script without the helper path; nothing set, nothing to restore), republished as -c at 21:07:10Z with the full grid (unlocked to 300 MHz, about 58 minutes). The site audit lane's row 17 and litepaper paragraph carry the 1,400 MHz rows labelled measured, with the best-points clause asked beside the 88 W at 1,400. THE 0.3.24 OBJECT COMMIT AND PIN: v5-object-0323 774f16c9 (21:26:35Z, both mirrors; the fork 432ea3d6 + f0c56f50 + 9ad1d9c6 + 294e3670 + the pool lane's 95ae3e50), paired with the frozen igneum-pow 1c420786: program_class_v5_activation_daa 28,800 (the Devnet 3 seed node at virtual DAA 16,208 at 21:22:24Z; the publish minute 22:30Z = DAA 20,264; plus 7,200 = 27,464; the next 3,600 boundary 28,800, epoch 8), byte 6 counted exactly, the window 86,400; the crossing on Devnet 3 by height about 00:52Z on 8 October (01:52 BST) at 1.0 DAA/s; the constant holds while the publish DAA stays at or under 21,600 (22:52:16Z), past which the node lane re-reads dn3-g1 and re-cuts to 32,400; chain id 4463 below the floor and 4464 from it; the three heights stay, the pool split never. Its gates: core 155 of 155, miner 28 of 28, pow 19 of 19, p2p-flows 38 of 38, exec 46 of 46, consensus 126 of 126 on the gate-priority rerun at 21:44:24Z (the earlier one red at 205 ms on the latency bound under a box load of 127, the known load class); the canary set on build-1 (21:29:38Z to 21:31:18Z): the digest moves to 4a284b1d on igneum-devnet-3 as the v5 arm requires, "this node stamps object version 6 into its headers (block version 1538)", the override file refused, two empty nodes handshake on 4a284b1d, the shared-devnet node refused on network mismatch, a 0.3.23 node refused on the digest both ways; every Devnet 3 node restarts inside one minute at the fleet's named clock on pre-placed binaries. release-0.3.24-node OPEN at 774f16c9 on both mirrors (21:45:19Z, the shipper's word), artefact /srv/artefacts/0324-774f16c9/node-lane (igneumd ed36f246...); the testnet staging 47b9b229 on the pin all green (consensus 134, core 175, exec 47, miner 28, p2p-flows 38, pow 19, digest b2e856ed). THE FAST-TIME GATE CLOSED: SUMMARY PASS (cross-c8f9b383-2) at 21:36:35Z on the matched pair c8f9b383 (igneumd f1b5b32c..., igneum-pow 1c420786), every check green, none skipped: class v4 sub-version 3 from genesis at rung 0; rung 1 by signal from epoch 6 at 21:29:39Z; class v5 by signal at byte 6 counted exactly from epoch 8 (DAA 480) at rung 1 at 21:31:33Z on 4 of 4 nodes, 9,985 bps, before the floor; the second rung at epoch 12 the rule's earliest allowed; 11 of 11 program ids equal to the CPU verifier's; 0 PoW rejections on the honest nodes; the stale node 69 of 69 refused; the restart step: n2 stopped at DAA 455, restarted on its own datadir at DAA 500 at 21:31:56Z, no lock fault, no IBD refusal, "class v5 catch-up done: 19 deferred headers validated after 6 s", nothing of its own accepted during the catch-up and 75 after, at n0's sink 12.1 s after its start; four sinks equal at 660; the digest-compat PASS from 20:08:30Z stands; records on v5-fasttime 4419e8d3. The three earlier pairs (959b57c9, 63524e28, 432ea3d6) each failed the restart step on a node defect fixed in the next (the IBD refusal, the catch-up's anchor at the node's own sink, the node mining while its catch-up waited). THE FLOOR READS EIGHT OF EIGHT (adv-accept, 22:41 BST): seed 122960 (the deepest live hot set) reads minimum site 12 at 0.9824 at the acceptance's 2^20 sample (live 0.9822), REFUSED by (c''') at 0.995 (its site 12 puts 1.31 percent of its reads on word indices read 8 or more times, the largest repeated-index share measured; 100767's site 6: 0.17); every live hot set by X_f at or above f found in the tail of 88,051 accepted programs is refused (minimum sites 0.9821 to 0.9919) against 0 hot sets in 20 random programs; the floor misses the three mild concentrations at 0.9992 to 0.9997 (Devnet 3's first program among them), about 1.0004x; the v5 design's section 14 and the ledger's AP-F8-1 carry the line. THE 0.3.24 CUT waits on the attack-pass verdicts on 1c420786 alone (F8's two halves on build-2 since 21:17:41Z, about 22:20 to 22:35Z; F9 at 10^5 and F1 on build-1); the lease pool now pre-empts adv holders at any size for a v5 or release waiter after 120 s (lease ce30e357). PC 1 EXCEPTION: the Power Helper task dies within seconds of each start since 21:08:34Z (six starts, zero commands, the task Running while no helper process exists; the last good command the 20:45:52Z rgc, its idle exit clean at 21:05:52Z); the suspect the shipper's 0.3.23 host job at 20:51Z replacing the install folder's exe under the registered task, the second a panic in the helper's start path; a read-only diagnostic plus a 20 s unelevated probe placed; the locked grids (the 5080 full grid, the third 5090 pass), the SM-sparse job and the tunes wait on the helper; the lock-free jobs run (the 9070 XT G1 and ladder from 21:27:41Z, then the family run and the v5 AMD bench); nothing raises a prompt to get round it. THE 5080 AT STOCK (two runs agreeing, -b and -c): class v4 71.42 MH/s at 254.5 W (0.281 MH/W, sm 2,960, mem 14,801), class v3 71.30 at 170.8 W (0.418), the premium 84 W; against the fleet's rented 5080 (71.16 MH/s at 145.4 W busy mean, cap 350 W not binding, 1 Hz power.draw instantaneous on Linux driver 580, bench batches with host gaps) the rate agrees to 0.4 percent and the watts do not (110 W apart, the sampler field on Blackwell under two drivers or the load shape); the public table carries the method per row and takes neither as the card's figure until both power fields are sampled on both sides (the fleet's re-measure, PC 1's next NVIDIA pass). THE CA4 SECOND PASS (bca23f96, sections 15 to 19): the tensor-tile k column (2.1x at k = 1, 1.6x at k = 1.5, the k 0.3 column removed for a tensor shadow; a design candidate needing a SIMD byte-dot verifier) and the capex column (the f = 1 GDDR7 chip USD 2.8 per MH/s, at most 4.3 with the hot table, the shadow core and an interposer; capex-dominated 7x; the break-even cap moving only through the project cost) carried into chip-model-v3 as section 5.11. THE PUBLIC TEXTS (main's two orders, 22:3x UK): the served sentence "the one outside check is staged and waits on its escrow and the publish word" read as an escrowed prize to a reader and is replaced everywhere it is served (evidence row 17, the litepaper and /claims through it, the public text file) by "no outside review has run yet", the in-house pass sentence kept; the forbidden-strings gate gains the phrase class ("outside check", "waits on its escrow", "staged and waits", "the publish word"; the bare words stay allowed, since the proving pool's escrow and a staged build are ordinary). THE /miners DESIGN PASS is on the mirror's ca3-coord at e88edae4 with the full gate GREEN (the overlap check clean at 390 to 1600 px after two fixes: the phone grid gives every cell its own area; the desktop row is six columns with the class v4 cost and the date as the muted second line under the card name, the card layout below 1,100 px, the wrapper scrolling as a safety); the 1440 and 390 dark captures go to main for the word on the look; nothing deploys from the branch before it. The in-house pass: four lanes complete (adv-cache, adv-accept-2, adv-cache-3, adv-mixer; adv-mixer's Q1 BOUND on the commutation probe at 0 in 1,454,080,000 over 1,024 days, its SAT row a solver-reach bound at the one-hour cap); adv-mixer-2 one row from complete; adv-accept, adv-accept-3, adv-cache-2 and adv-mixer-3 sweeping to 00:00 BST. A SHARED-DEVNET FACT FROM THE FLEET (not this lane's, with the shipper and the infra lane): the Hetzner live seed 188.245.5.161:26611 is still on the old override object (digest eada4bda) 1 h 40 min after the 0.3.20 sweep (the fleet never touches Hetzner nodes, so it was outside the sweep); the 0.3.21 wipe canary c22-1 took five digest-mismatch rejects from it; an app with the packaged peers is refused at the seed and syncs through node1 and the hub only, a fresh joiner with only the seed cannot join, the 14 voters and the hub are unaffected; the owner puts the floor file ov16-floor-900000.json (sha 294f1f80) and the c4459193 pin on it. 0.3.21's STAGING (the node lane): the order dry-merges onto 55768f88 with nothing moving to 0.3.22; the late-join fix is 52e96c94 (70e4601e rebased onto 55768f88, exec suite 33 green with both new tests); f067f7c1, b0444f51 and 437f0438 merge clean in order; 2e32d5f6's one conflict (DST_ADDRESS beside pool-finish's DST_BINDING in consensus/core/src/finality.rs) kept both; the live-file digest eada4bda after each (every switch at never); the staging waits on the shipper's sweep-end word; the re-pin held. PC 2 DOWN AGAIN (main, 16:5x UK): the founder takes PC 2 down for cable work (PC 1 back but his desk); both PCs out of the sweep's waves, each updates on its poller on return; no PC job to PC 1; the Windows G1 completed before the outage, nothing reruns. 0.3.21's SECOND GATE LINE on 55768f88 (sha256 279b1b690e854fc9): the ten-minute mixed-version gate beside the 5899f603 pair, 13:37:40Z to 13:47:52Z, SUMMARY PASS (one digest b0afb2ee on five nodes; 223 new and 381 old blocks accepted by the old hub, 0 rejected; counts equal at 319, 486 and 604 through both clean joins and the restart step at 13:45:22Z; no panic); the node lane's two lines on 0.3.21's first candidate complete, in plan 6.9 on ca3-v4-node; the fleet's set on it (the bare-child 12 GB line, the wipe, the kept read, the cases) is the fleet's. 0.3.21's FIRST GATE LINE on 55768f88 (sha256 279b1b690e854fc9, the string read back; pairing igneum-pow 8c728ca3 at byte 5): the digest gate 13:35:41Z to 13:37:19Z SUMMARY PASS (a89be8a7 on both binaries with the peers; db9a85f9 refused, no peer; the live file's eada4bda unmoved); the ten-minute mixed-version gate from 13:37:40Z, line about 13:50Z. The 0.3.21 order as the shipper sent it: 55768f88; f067f7c1 and 70e4601e; b0444f51; 6eb21fc9; db28d331; then the re-pin from 8bdcbdd8 on the coordinator's word; suites between, the digest read after every one; the mirror's release-0.3.20-node back at the pin c4459193, release-0.3.21-node open at 55768f88. THE LATE-JOIN COMMIT (N9's second half, the node lane): 70e4601e on the box mirror as branch proof-hold-fix, from c4459193, two files (igneum/exec/src/proving.rs, protocol/flows/src/v10/proving.rs); the gap was the fetch side on the joiner (the served record ran the native check against the joiner's trailing exec state before anything was stored, the check refused it, the proof was never held, the body rule read "not held" for 20 s and failed the IBD); the fix holds the proof by hash before the checks (the pool entry still needs them) and the serve side says when it holds fewer than asked; the exec suite 32 passed at 13:26Z with the known-failed shape first, the flows check green 13:28Z, igneumd on build-1 at the 0321 worktree path built 13:32Z, sha256 17649eeb2f7d1290, string read back; with the testnet lane (the resume form, B alone); it joins the 0.3.21 staging as its own commit. THE WIPE CANARY ON c19-1, c4459193 (sha 45be9b02d1b002f5, string read back): FORM END rc 0 at 13:50:53Z. Wipe synced 13:35:50Z (57 minutes, inside the 98-minute class); mining 13:36:00Z to 13:47:07Z, 66 mined, 66 accepted, 0 rejected, isSynced true at the tip throughout; the hub holds 41 of its blocks in its last 700 with 0 rejects (13:47:09Z); the restart on its kept datadir at 13:47:15Z: the old process stopped at once (the new process's first lock line seven seconds after the marker; the watchdog held nothing, the b7cc37e7 fault closed), synced again at 13:48:39Z after 84 s, 109 templates read with max 3,432 ms and 0 timeouts; the kept read on pool-1's 0.3.17 copy on the same pod passed at 13:38Z (the rewrite line once, a clean second start). The pin's set on c4459193: the digest gate PASS, the mixed-version gate PASS, the wipe canary PASS, the kept read PASS, the restart PASS, the 12 GB line proves and verifies (paid is a race, not a gate); CASES END from c20-1 (about 14:50Z) is the last pin line. THE INTEROP FACT stands from the void run: the 5899f603 hub accepted 235 object-byte-5 blocks from the 8097d600 node with 0 rejected, one digest on all five nodes on the live sixteen-field file. The gates: the digest test and the kaspa-pow vector test (the amended devnet epoch-0 id 1a4230699a6b9c60 must equal, c120d7963abdcd96 must differ, the v3 control unchanged) on the box; the mixed-version Devnet 2 gate (the amended 0.3.20 node beside a 5899f603 node for ten minutes on the live file without the v4 fields) after the Mac build; the fresh-join canary the 0.3.20 cut's | | Main's rulings (7 October, morning) | no generator change to v4 on the live devnet; the record's null is the window model with numbers, sent by the hash lane to the attack-pass lane so AP-F8-1 re-gates against it; a fault beyond the model (a low-entropy source at site 15) stops at the coordinator with the two options priced (a 0.3.19 class amendment before the flip, or the flip held at the floor), nothing shipping without the founder's word; the tighter tail, an acceptance bound on the hot-set share, is a CLASS V5 item (sent to the v5 lane a6410f3b8abefb762 with the 64-seed census as its gate; the bound's number follows from the model) | ### AP-F4-1, the weak-day MUL draw (the attack-pass lane, 7 October, morning): PASS against v4, a class v5 rule diff --git a/site/claims.html b/site/claims.html index 347fd71c5..f86f4de02 100644 --- a/site/claims.html +++ b/site/claims.html @@ -229,6 +229,10 @@
  • A cryptography team. Not yet. One founder working with AI systems wrote the design and the code; external reviewers are named and paid before gate 3, and every security claim here is a design claim until then.
  • Finality that no amount of hardware can break. No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded by the 12-hour finality depth. Reaching a third takes at least ten days of producing every block on the chain, in public; an attacker matching the honest network needs twenty days for a third and never reaches two thirds. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose. The floor is also bounded in time: an honest partition that lasts long enough for each side's own new blocks to reach two thirds of its window locks on both sides, about ten days of a 30-day window at an even split, and an operator must then resolve it (measured on a test network, 4 October 2026).
  • Finality that never pauses. No. A lock needs two thirds of all 30-day mining weight. Whenever less than two thirds of that weight is connected and signing, finality pauses until it returns or ages out of the window, up to 30 days. The chain keeps running on proof of work and the node reports the pause.
  • +
  • A label that costs nothing. No. Some investors and exchanges read "GPU-mined" as 2021 whatever the proofs do, and nothing here measures that cost. The only evidence will be whether the first miner apps and verifiable-compute apps sign despite the label.
  • +
  • A chain you can debug today. Not yet. The node does not serve debug_traceTransaction, eth_subscribe or eth_getProof, and there is no public RPC, faucet or explorer for the devnet. They come in a fixed order (docs and templates, then the tracing and subscription RPCs, then a public RPC, listing and faucet, then the explorer) and no outside team is invited to build before the second step is done.
  • +
  • A veto on job results. No. A segment proof is checked against every node's own execution; a proving job for another chain is not, because no full node can re-run an arbitrary program, so a soundness bug in the proof system in force reaches the requesting contract. A job output can mint nothing and touch no system contract, and an app that acts irreversibly on a job result keeps its own fallback.
  • +
  • A delay function that outlives a quantum computer. No. The class-group delay between a locked checkpoint and the next program seed falls to the same machine that would forge the vote keys; it is flagged in the specification, not yet sized, and the fallback is a hash-chain delay behind the same version byte that moves the signature scheme, so both flip in one class change. A grindable hourly seed is a liveness nuisance against the lottery, not a break of finality.
  • A finished protocol. The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.
  • Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything. Found an error, or a criticism this document does not answer? Email hello@igneum.network, or open an issue on the public specification repository: git.igneum.network/igneum-network/spec/issues. Post reaches Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre.

    diff --git a/site/evidence.html b/site/evidence.html index a24934014..081cd0489 100644 --- a/site/evidence.html +++ b/site/evidence.html @@ -254,7 +254,7 @@ td.mono{font-family:var(--f-mono);font-size:12.5px;min-width:180px}td.iv{color:v 14Ethereum bytecode runs unchanged, with the documented differences of spec 7.1
    Homepage Build card; litepaper Building
    tested by the teamas row 13; fixes F-exec-A, F-exec-B (spec 7.5)tools/evm-smoke/smoke.mjs: deploy via viem, increment, hashLoop, eth_estimateGas, eth_getLogs; tools/exec-attacks scenarios 1 and 3; bench-log "execution layer attack fixes"Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The Prover precompile, proof records and the shard planner are not in the nodenone yet 15Every block is proven, with the proof landing within about a minute at launch
    Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate
    implementedrepo d7e1f89 (GPU proof), e01a3cc, 292e800, eedd136 (proving/igneum-prove: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6proving/windows-wsl2 (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; igneum-prove-host --mode block on proving/fixtures/; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards"First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture block-78-increment (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in docs/benchmarks/proving-e2e.md. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on the RTX 5090 Windows rig in 34 s, verified on the Apple M5 Max in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind proving_v1_activation_daa (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is onenone yet 16A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves)
    Litepaper Proving ("The proving budget"); roadmap gate 2
    designedspec 5.1 (Target), 7.6 (S_p provisional, 7,500,000 pgas = B_p / 4)PROVE-SHARD.bat on the RTX 5090 (pending); the end-to-end standard in docs/benchmarks/proving-e2e.md; bench-log "proving: devnet v4 shards"Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional S_p is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB cardnone yet -17The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)
    the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line
    tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measureddocs/analysis/chip-model-v3.md 5 and 6; docs/analysis/latency-shadow-2026-10-06.md; docs/plans/counter-asic-3-status.md; docs/analysis/attack-pass/f8-uniform.md, f4-weakday.md, docs/analysis/ca3-v4-uniform.md; docs/design/class-v5-stored-state.md; the H100 and market-cap rows of 7 October; docs/plans/cryptanalysis/in-house-pass.md (the internal adversarial pass)the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses tools/attack/f8-uniform and the F4 census; the verifier by igneum-pow bench136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026).none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and the one outside check is staged and waits on its escrow and the publish word +17The chip resistance claim: at launch the strongest chip in the public model reaches 2.1x (a core as good as a GPU lane, k = 1) to 3.4x (a core three times better, k about 0.33) per joule against an RTX 5090 under class v4, live from genesis on the testnet and the mainnet; the ladder's second rung brings it to about 2.8x; class v5 makes the dataset the chain's state so a stateless or stale chip is wrong on every item; the hot-set cache is bounded at 1.067x at the ceiling and the weak-day FPGA at 12 percent on 15 days a century, both routed to the next class; datacentre silicon does not change the question; a stored-dataset chip pays for itself only at about USD 100 M of market cap in two years; without class v4 the same chip would reach 5x to 9x (the class v3 baseline, the devnet's starting state, never the launch state)
    the home page's chip line, the litepaper's chip section (/litepaper#chip-model), the miner page's line
    tested by the team (every card, the verifier, the two attack-pass bounds, the H100), the chip itself modelled, class v5 and the ladder designed, the X9 figure claimed against a CPU core and never measureddocs/analysis/chip-model-v3.md 5 and 6; docs/analysis/latency-shadow-2026-10-06.md; docs/plans/counter-asic-3-status.md; docs/analysis/attack-pass/f8-uniform.md, f4-weakday.md, docs/analysis/ca3-v4-uniform.md; docs/design/class-v5-stored-state.md; the H100 and market-cap rows of 7 October; docs/plans/cryptanalysis/in-house-pass.md (the internal adversarial pass)the chip model's arithmetic in its file; the card rows by the benchmark package; the attack-pass harnesses tools/attack/f8-uniform and the F4 census; the verifier by igneum-pow bench136 MH/s at 350 W (5090, bench) and 290 W (app); 27 MH/s at 21 W (M5 Max); 249 MH/s (H100 SXM) at 98 percent of its read ceiling, 1.78x hash, 1.15x MH/W, a third per rented dollar; 2.33 ms per warp; 2.1x, 3.4x, 2.8x at launch; the shadow's premium on a 5090 81.8 W at its knee (class v4 at the 1,200 MHz lock 133.80 MH/s at 305.1 W; class v3 at 1,300 MHz 134.62 at 223.3 W; 7 October 2026); 1.067x at the ceiling; 12 percent on 15 days a century; 10.85 ms at rung 3; USD 100 M; 5.1x to 9.2x the class v3 baseline; 6 and 7 October 2026, the M5 Max, the RTX 5090 Windows rig's RTX 5090, the three-card Windows rig's RX 9070 XT and RTX 4070, a rented H100 SXM, igneum-build-1 The k about 0.33 bound is the implied core of Bitmain's Antminer X9 (RandomX; 1,000 KH/s, 2,472 W, 2.47 J per KH, USD 5,600; pre-orders 26 December 2025), withdrawn in mid-May 2026 with buyers refunded before any unit shipped, no independent benchmark, commodity Sophgo SG2044 server SoCs with an AES accelerator, no tapeout: a claimed, unmeasured figure carried as the pessimistic bound, not a calibration point (attack pass AP-F5-1, 7 October 2026).none yet; the next test is the internal adversarial pass (three lanes new to the hash code, outsider inputs only, reports published whole), and no outside review has run yet 18The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache
    Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page
    tested by the teamreadwidth e752fc7 (docs/plans/read-width.md), ca2-era 78c0ee4, ca2-cache 2de19e5 (docs/plans/hot-table.md)The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per loadLatency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026none yet 19The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors
    Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page
    tested by the teamca2-mixer 1ab8b21 (tests/mixer.rs, tests/scratch.rs), ca2-era 78c0ee4, ca2-soundness a465881 (docs/analysis/scratch-soundness.md), igneum-pow/tests/packs.rsThe crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per cardClass v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (the three-card Windows rig (RTX 5090, RTX 4070, RX 9070 XT) job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing)none yet 20No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%)
    Homepage stats and Economics tiles; litepaper Supply, Economics
    implementedrepo 6ac80a3; fork "igneum-node devnet v0"; consensus/core/src/igneum.rs, coinbase.rscargo test -p kaspa-consensus-core igneum (8 pass: subsidy table, ramp, split, cap) and cargo test -p kaspa-consensus coinbase (8 pass); igneum-miner inspect 40; bench-log "igneum-node devnet v0"Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the igneum-proving-pool-v0 output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happenednone yet diff --git a/site/forbidden-strings.txt b/site/forbidden-strings.txt index ac88ce391..eec90bffd 100644 --- a/site/forbidden-strings.txt +++ b/site/forbidden-strings.txt @@ -38,3 +38,8 @@ disclosure prize # the rig names never reach a served page (verification lane, 7 October 2026: a substring grep read "PC 2" inside gRPC port numbers; this is the word-bounded check) \bPC [12]\b counsel is engaged +# 7 October 2026 (main's rule): the one outside check is never hinted at before its time; the phrase class, not the bare words (the proving pool's escrow and a staged build are ordinary) +outside check +waits on its escrow +staged and waits +the publish word diff --git a/site/litepaper.html b/site/litepaper.html index cf8cf3082..defe6ddf3 100644 --- a/site/litepaper.html +++ b/site/litepaper.html @@ -449,7 +449,7 @@ body.all .pager{display:none} When a stored-dataset chip pays for itselfat about USD 100 M of market cap in the first two years, not beforemodelled, 7 October 2026 The baseline the work started from: the same chip under class v3, without the shadow (the Ethash class)5x to 9x (5.1x on GDDR7, 9.2x on eight HBM3 stacks; the Ethash chips of this class reached 2.1x to 4.8x)modelled, 6 October 2026; the precedent measured by others, 2020 to 2022; never the launch state -

    What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). Devnet 3 runs class v4 from its first block (7 October 2026); the first devnet started on class v3 and reaches class v4 by miner signal at a published height. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. The one outside check is staged and waits on its escrow and the publish word.

    +

    What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). Devnet 3 runs class v4 from its first block (7 October 2026); the first devnet started on class v3 and reaches class v4 by miner signal at a published height. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet.

    No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the response takes a week, and both are measured. The model is public: the numbers; the claim is tested by the in-house adversarial pass and the public benchmark. Monero has run on RandomX since 2019 (approximate) with no chip shipped. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. A box with about a 2x per joule edge over the best CPUs, and about 3x over a desktop, was withdrawn rather than face a RandomX re-tune of 1.5x or more. That is the band Igneum’s class v4 model sits in (2.1x to 3.4x over an RTX 5090), and the defence that held was a maintained algorithm with a credible upgrade path, which is what the ladder is.

    One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.