E15 decided: the 4 billion cap stays, no tail emission; spec 5.10 with the measured security-budget table and the review trigger, O-5.11 closed, litepaper and homepage state the cap and the years
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
4967dae3b1
commit
8f2cd23f04
5 changed files with 58 additions and 5 deletions
|
|
@ -1387,7 +1387,7 @@ Evidence: E4, E5, G1, G5; fud-fixes rows 47, 50, 71. Decision: the project lead,
|
|||
### E15. The security budget through successive halvings with low fees and no external demand
|
||||
"Walk the schedule forward: emission halves every two years, the base fee is burned, the priority fee is small on a quiet chain, and nobody buys proofs. What does a card earn in year 7, and at what price does hashrate leave? Report what reaches miners and provers apart from what is burned."
|
||||
|
||||
Status: Answered with evidence (model; 5 October 2026 sweep). `docs/analysis/security-budget.md` (3 October) walks the schedule through six halvings at three flat prices: emission to miners falls below a USD 1,000,000 floor (the power of about 3,000 cards) in year 7 at USD 0.005, year 11 at USD 0.02, and not within 14 years at USD 0.10. `sim/economy/security_budget.py` (new tonight, `python3 sim/economy/security_budget.py`) adds a fee grid (0, 0.01, 0.1 and 1 IGN of tips per block; external demand 0 or USD 2,000 a day), a falling (-30% a year) and a rising (+30%) path, and the hashrate response at USD 0.12 per kWh, 300 W and 124 MH/s per card. Result: no fee level in the grid moves the crossing year (1 IGN per block of tips is 12.6 million IGN a year to miners, under a tenth of year-7 emission); the falling path crosses in year 5, the rising path never. What the budget buys at the crossing: at USD 0.005 in year 7 the miners' USD 500,000 pays the power of 1,584 cards (196 GH/s at today's 5090 rate), and a 51% attacker matches that fleet for USD 1,369 of electricity a day, USD 27,379 for the 20-day two-thirds campaign (year 1 at the same price: 12,206 cards, USD 10,546 a day, USD 210,924 for 20 days). Those are power-only upper bounds for the fleet and lower bounds for the attack. The litepaper sentence is public text (testnet-prep). Was: Open, simulation scheduled (O-5.11); extends E1 and E6.
|
||||
Status: Decided (5 October 2026, morning, by the owner): the 4,000,000,000 IGN hard cap stays absolute and there is no tail emission. The security budget after the subsidy fades is the proving market (external proof jobs, dollars-priced work settled in the token, 90% to provers, spec 5.4) plus fees (spec 5.2); provers' income does not depend on emission. Review trigger, spec 5.10.3, written as a rule: if external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the tail-reward question goes to the miners' signalling vote (spec 5.7 and 5.8, encoding O-5.3), and the protocol itself never changes emission without that vote. Evidence: `python3 sim/economy/security_budget.py` (5 October 2026, defaults: USD 0.12 per kWh, 300 W, 124 MH/s a card): the subsidy to miners alone is under the USD 1,000,000 floor (the power of 3,169 cards) from year 7 at USD 0.005, year 11 at USD 0.02, never within 14 years at USD 0.10; at the crossing USD 500,000 powers 1,584 cards and a 51% attacker matches them for USD 1,369 of electricity a day, USD 27,379 over 20 days; no fee level in the grid moves a flat-price year; the -30% a year path crosses in year 5 (year 6 at 1 IGN of tips a block with launch demand), the +30% path never. Stated in spec 5.10 (table, decision, trigger), spec 06 O-5.11 (decided), the litepaper Economics section ("Security after the subsidy") and the homepage economics tile. Was: Answered with evidence (model; 5 October 2026 sweep). `docs/analysis/security-budget.md` (3 October) walks the schedule through six halvings at three flat prices: emission to miners falls below a USD 1,000,000 floor (the power of about 3,000 cards) in year 7 at USD 0.005, year 11 at USD 0.02, and not within 14 years at USD 0.10. `sim/economy/security_budget.py` (new tonight, `python3 sim/economy/security_budget.py`) adds a fee grid (0, 0.01, 0.1 and 1 IGN of tips per block; external demand 0 or USD 2,000 a day), a falling (-30% a year) and a rising (+30%) path, and the hashrate response at USD 0.12 per kWh, 300 W and 124 MH/s per card. Result: no fee level in the grid moves the crossing year (1 IGN per block of tips is 12.6 million IGN a year to miners, under a tenth of year-7 emission); the falling path crosses in year 5, the rising path never. What the budget buys at the crossing: at USD 0.005 in year 7 the miners' USD 500,000 pays the power of 1,584 cards (196 GH/s at today's 5090 rate), and a 51% attacker matches that fleet for USD 1,369 of electricity a day, USD 27,379 for the 20-day two-thirds campaign (year 1 at the same price: 12,206 cards, USD 10,546 a day, USD 210,924 for 20 days). Those are power-only upper bounds for the fleet and lower bounds for the attack. The litepaper sentence is public text (testnet-prep). Was: Open, simulation scheduled (O-5.11); extends E1 and E6.
|
||||
|
||||
Answer: Correct that the ledger concedes the cliff (E1) and the halving bet (E6) and has computed neither. O-5.11 is a model: emission per spec 2.5 through year 12; a fee grid (priority fee per block at low, medium and high use; external jobs at zero, low and the brief's launch assumption); hashrate as a function of income per card at a stated electricity price under a flat, a falling and a rising IGN price; reporting per year the payments to miners and to provers apart from the burn, the hashrate that income supports, and the cost of a 51% rental against it. The honest output is the year and the price at which the budget fails under the no-demand, flat-price case, stated in the litepaper's Supply section next to the tail-emission alternative. The flat-price column is the one that counts.
|
||||
|
||||
|
|
|
|||
|
|
@ -1,6 +1,6 @@
|
|||
# Igneum protocol specification, section 5: fees, splits, burns, signalling
|
||||
|
||||
Spec version 0.1, 3 October 2026. Status of this section: Designed (design document, "The token", "Finality rule, version 2: Fees", decisions table "What do I get for being early?"). Nothing here is implemented or measured. Emission itself is section 2.5.
|
||||
Spec version 0.1, 3 October 2026. Status of this section: Designed (design document, "The token", "Finality rule, version 2: Fees", decisions table "What do I get for being early?"). Nothing here is implemented or measured, except section 5.10, which is Decided (5 October 2026) and carries a simulation. Emission itself is section 2.5.
|
||||
|
||||
Two rules frame everything: there is no stake anywhere in consensus, and the protocol carries no fee to any team, foundation or fund. Not one unit of emission or of fees goes to a treasury, a fund, a founder or a stake. The development fund that earlier drafts carried (5% of tips and 5% of job fees under 60% signalling) was removed on 3 October 2026 (section 5.5).
|
||||
|
||||
|
|
@ -85,3 +85,46 @@ Designed, Open (O-5.3). Each block carries a bitfield; bit b set means "this blo
|
|||
| Proving-cost budget per block | from the phase 2 measurement | Target |
|
||||
| Emission to any treasury | 0 | Designed |
|
||||
| Protocol fee to any team, foundation or fund | 0 | Designed (3 October 2026) |
|
||||
| Tail emission | 0; the 4,000,000,000 IGN cap of section 2.5 is absolute | Decided (5 October 2026, section 5.10) |
|
||||
| Tail-reward review trigger | external proving revenue under 1/5 of the block subsidy over any 90-day window after year 5 puts the question to the miners' vote (5.7); the protocol never changes emission by itself | Decided (5 October 2026, section 5.10.3) |
|
||||
|
||||
## 5.10 Security budget after the subsidy
|
||||
|
||||
Decided 5 October 2026 by the owner: the 4,000,000,000 IGN hard cap of section 2.5 is absolute and there is no tail emission. The security budget after the subsidy fades is the proving market (external proof jobs, dollars-priced work settled in the token, 90% to the provers who delivered, section 5.4) plus fees (the 80% producer-and-prover share of the priority fee, section 5.2). Ledger E15; open item O-5.11, decided.
|
||||
|
||||
### 5.10.1 What the subsidy alone pays for
|
||||
|
||||
Measured by `python3 sim/economy/security_budget.py` (5 October 2026, default arguments; the floor is from `docs/analysis/security-budget.md`, 3 October 2026, section 6). The assumptions, every one an input and none a prediction:
|
||||
|
||||
| Input | Value |
|
||||
|---|---|
|
||||
| Emission | section 2.5: 1,000,000,000 IGN a year of 365.25 days in years 1 and 2, minus the 30-day ramp in year 1 (about 37,000,000 IGN never minted), halving every 63,115,200 DAA s; 80% to miners, 20% to the proving pool |
|
||||
| Price | flat at USD 0.005, 0.02 and 0.10 per IGN for 14 years; and the base price USD 0.02 on a falling path (-30% a year) and a rising path (+30% a year) |
|
||||
| Fees | a priority-fee grid of 0, 0.01, 0.1 and 1 IGN a block at 1 block/s, 80% to miners and provers split 50/50; external demand 0 or USD 2,000 a day, 90% to provers; the base-fee burn reaches nobody and is not counted |
|
||||
| Card | 300 W at 124 MH/s (the RTX 5090 on the devnet, 4 October 2026); electricity USD 0.12 per kWh; USD 315.58 of power per card-year |
|
||||
| Floor | USD 1,000,000 a year to miners: the power of 3,169 such cards ("about 3,000"; 393 GH/s), the fleet at which one 1,000-card operator holds a third of the 30-day vote weight |
|
||||
| Fleet | the cards whose power the miners' subsidy pays at break-even; capital, rent and margin are zero, so the fleet is an upper bound |
|
||||
| Attacker | a 51% attacker matches that fleet for 24 h at the same electricity price, a lower bound on the attack; the 20-day figure is the two-thirds campaign of section 3 (20 days of 100% of hashrate) |
|
||||
|
||||
The years at which the subsidy alone, with no tips and no external demand, pays miners less than the floor:
|
||||
|
||||
| Flat price, USD per IGN | First year under the floor | Subsidy to miners that year, USD | Cards that subsidy powers | 51% attacker's electricity, USD a day | 20-day campaign, USD |
|
||||
|---|---|---|---|---|---|
|
||||
| 0.005 | 7 | 500,000 | 1,584 | 1,369 | 27,379 |
|
||||
| 0.02 | 11 | 500,000 | 1,584 | 1,369 | 27,379 |
|
||||
| 0.10 | none within 14 years (the row shows year 14) | 1,250,000 | 3,961 | 3,422 | 68,446 |
|
||||
|
||||
For scale, year 1 at USD 0.005: 3,852,000 to miners, 12,206 cards (1.51 TH/s), USD 10,546 of attacker electricity a day, USD 210,924 over 20 days. The crossing year is the same at every fee level in the grid: 1 IGN a block of tips is 12,623,040 IGN a year to miners, about a tenth of year-7 emission. The falling path crosses in year 5 at every fee level except the highest (1 IGN a block with launch demand), where it crosses in year 6; the rising path never within 14 years. Readers with another electricity price or card can re-run the script with `--elec`, `--card-w` and `--card-mh`; a 2x change in the floor moves the year by at most one halving.
|
||||
|
||||
### 5.10.2 The decision and the reasoning
|
||||
|
||||
The cap stays. Provers' income does not depend on emission: a prover is paid per job (90% of the job fee, 5.4) and per block from the tip share (5.2), and both scale with demand for proofs and for block space, not with the schedule. The 20% emission share is a launch subsidy for a standing prover population; when it fades, the proving market is what keeps the cards on, and a card that is on can hash. The subsidy to miners fades on the schedule every capped proof-of-work chain shares; here the years are measured and stated, and the same hardware has a second income that emission never paid. A tail reward is ruled out as a protocol default, not for ever: the trigger below says when the question is put to the miners, and only their vote can change the schedule.
|
||||
|
||||
### 5.10.3 Review trigger
|
||||
|
||||
REVIEW TRIGGER (rule). If external proving revenue is under one fifth of the block subsidy over any 90-day window (7,776,000 DAA s) after the end of year 5 (DAA score 157,788,000), the question of a tail reward goes to the miners' signalling vote. The protocol itself never changes emission without that vote.
|
||||
|
||||
- External proving revenue: job fees settled in IGN under 5.4, counted at settlement over the window. Until jobs settle in IGN (O-5.2), it is what the payout contracts on customer chains received over the window, converted at the window's settlement rate and published with the reading. Block subsidy: `E(t)` of section 2.5 summed over the same window, in IGN.
|
||||
- The reading is made by people from chain data and published. The chain computes nothing and changes nothing.
|
||||
- The vote: a tail reward changes a consensus constant fixed at genesis, so it is an upgrade under 5.7 (90% of blue blocks over the window of O-5.3), not a 60% parameter. Anyone may register the proposal under 5.8 once the condition has held; a proposal that fails may be re-registered after the next qualifying window.
|
||||
- Nothing in this rule obliges the vote to pass. The cap is the default; a tail reward is a change miners may adopt, and the protocol never adopts it by itself.
|
||||
|
|
|
|||
|
|
@ -94,7 +94,7 @@ An item closes when its measurement is in `docs/bench-log.md` or its decision is
|
|||
| O-5.8 | Developer registration format at deployment and the re-registration transaction (section 5.2) | Execution-layer specification | decision, execution engineer |
|
||||
| O-5.9 | Mining against proving under shocks: external proving pays 10x, the IGN price falls, a large operator leaves, assignments go unfulfilled, clients maximise profit (ledger E12); design R8 covers the fee switch only and has not run | R8 simulation extended with the five shocks, then the phase 4 devnet with profit-only prover clients: backlog depth, time to clear, `f_p` and `B_p` paths, income per card. Sweep 5 October 2026: the simulation half ran in `sim/economy` (scenarios b, d, e: external 10x with a 70% price fall, the 20% operator leaving, a 30% operator never fulfilling; no backlog, every block proven within 60 s, hash trough 82% and 75%); the devnet half with profit-only clients is fud-fixes row 126 | 4 |
|
||||
| O-5.10 | No single figure shows every payment route (emission, base fee, priority fee, external jobs at launch and after the bridge, the client dev fee) with currency, recipient, fee and burn (ledger E13) | Draw it, one route per row, in the litepaper Economics section and the customer brief; operator revenue never summed with protocol revenue | decision, execution engineer; before public repo |
|
||||
| O-5.11 | Security budget through halvings with low fees and no external demand at a flat IGN price (ledger E15) | Model of emission per 2.5 through year 12 against a fee grid and an income-per-card hashrate response; payments to miners and provers reported apart from the burn; the failing year and price stated in the litepaper. Sweep 5 October 2026: ran as `docs/analysis/security-budget.md` (3 October) plus `sim/economy/security_budget.py` (fee grid, falling and rising paths, hashrate response): the USD 1,000,000 miner floor is crossed in year 7 at USD 0.005, year 11 at USD 0.02, never within 14 years at USD 0.10; no fee level in the grid moves the year; at the year-7 crossing a 51% attacker matches the fleet the budget pays for at USD 1,369 of electricity a day. The litepaper sentence is public text | before mainnet, simulation |
|
||||
| O-5.11 (decided) | **Decided 5 October 2026 by the owner: the 4,000,000,000 IGN cap is absolute, no tail emission (section 5.10).** The question was the security budget through halvings with low fees and no external demand at a flat IGN price (ledger E15), and whether a tail reward answers it. Measured by `docs/analysis/security-budget.md` (3 October) plus `python3 sim/economy/security_budget.py` (5 October 2026: fee grid, falling and rising paths, hashrate response at USD 0.12/kWh, 300 W, 124 MH/s): the subsidy to miners alone is under the USD 1,000,000 floor (the power of 3,169 cards) from year 7 at USD 0.005, year 11 at USD 0.02, never within 14 years at USD 0.10; no fee level in the grid moves a flat-price year; at the crossing USD 500,000 powers 1,584 cards and a 51% attacker matches them for USD 1,369 of electricity a day, USD 27,379 over 20 days. The security budget after the subsidy is the proving market plus fees; provers' income does not depend on emission | Closed. Section 5.10 states the table, the decision and the review trigger (5.10.3): if external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the tail-reward question goes to the miners' signalling vote (5.7, 5.8; encoding O-5.3) and the protocol never changes emission without it. The litepaper Economics section and the homepage state the cap, the years and the trigger | decided; the trigger stands |
|
||||
|
||||
## 6.6 Sections 7 and 8, execution and client security
|
||||
|
||||
|
|
@ -126,7 +126,7 @@ Added 3 October 2026 (night) from the external review. These items belong to no
|
|||
| 2 | 9 (O-2.8 closed 3 October 2026 by section 7.1) |
|
||||
| 3 | 16 (O-3.3 and O-3.7 narrowed to parameters and confirmation on 3 October 2026; O-3.14 added the same evening, round 3; O-3.15 and O-3.16 added the same night, external review) |
|
||||
| 4 | 9 |
|
||||
| 5 | 11 (O-5.1, O-5.2 and O-5.6 narrowed on 3 October 2026; O-5.9 to O-5.11 added the same night, external review) |
|
||||
| 5 | 11 (O-5.1, O-5.2 and O-5.6 narrowed on 3 October 2026; O-5.9 to O-5.11 added the same night, external review; O-5.11 decided 5 October 2026, section 5.10) |
|
||||
| 7 | 2 (added 3 October 2026, night) |
|
||||
| 8 | 3 (O-8.2 and O-8.3 added the same night) |
|
||||
| X (6.8) | 3 |
|
||||
|
|
|
|||
|
|
@ -493,7 +493,7 @@ pre{margin:0;font-family:var(--f-mono);font-size:13px;line-height:1.6;color:var(
|
|||
<div style="display:grid;gap:48px;grid-template-columns:repeat(auto-fit,minmax(min(100%,380px),1fr));align-items:center">
|
||||
<div class="reveal" style="display:flex;flex-direction:column;gap:20px">
|
||||
<h2>Every coin, mined</h2>
|
||||
<p style="color:var(--ink-2)">Hard cap of 4 billion IGN, halving every two years for ever.</p>
|
||||
<p style="color:var(--ink-2)">Hard cap of 4 billion IGN, halving every two years for ever. The cap stays. After the subsidy, the proving market and fees pay for security. The litepaper has the measured years and the review rule.</p>
|
||||
<div style="display:flex;flex-direction:column;gap:10px">
|
||||
<div class="bar" id="bar"><div style="width:0;background:var(--ember)" data-w="80%"></div><div style="width:0;background:var(--molten)" data-w="20%"></div></div>
|
||||
<div class="legend mono" style="margin-top:4px;font-size:13px">
|
||||
|
|
|
|||
|
|
@ -502,6 +502,16 @@ body.all .pager{display:none}
|
|||
</table></div>
|
||||
<h3>Where fees go</h3>
|
||||
<p>The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits two ways: 80% to the miner and provers of that block, 20% to the apps whose code ran, by gas consumed inside each. External proving fees pay 90% to the provers who delivered and burn 10%. The hard cap fixes supply. Emission is untouched by any of this: every coin minted still goes to miners and provers.</p>
|
||||
<h3>Security after the subsidy</h3>
|
||||
<p>The cap stays at 4 billion. There is no tail emission. Long term, security is paid for by the proving market and by fees. Outside customers buy proofs as dollars-priced work settled in IGN, and 90% of every job goes to the provers who delivered it, so a prover's income does not depend on emission. The table shows the first year in which the block subsidy on its own pays miners less than the power of about 3,000 consumer cards, at three flat prices. The prices are inputs chosen to span two orders of magnitude. The model runs a 300 W card at 124 MH/s on electricity at USD 0.12 per kWh. One rule sits beside the cap. If external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the question of a tail reward goes to the miners' signalling vote. The protocol never changes emission by itself.</p>
|
||||
<div class="tbl"><table>
|
||||
<thead><tr><th>Price per IGN</th><th>First year the subsidy alone pays under the power of 3,000 cards</th><th>Subsidy to miners that year</th></tr></thead>
|
||||
<tbody>
|
||||
<tr><td class="num">USD 0.005</td><td>Year 7</td><td class="num">USD 500,000</td></tr>
|
||||
<tr><td class="num">USD 0.02</td><td>Year 11</td><td class="num">USD 500,000</td></tr>
|
||||
<tr><td class="num">USD 0.10</td><td>None in the first 14 years</td><td class="num">USD 1,250,000 in year 14</td></tr>
|
||||
</tbody>
|
||||
</table></div>
|
||||
<h3>No fund, no foundation, no fee to the team</h3>
|
||||
<p>There is no development fund. A switch that routes money to an address somebody controls is the first thing a critic points at, so Igneum has none. The protocol carries no fee to any team, foundation or fund. The team earns in the open: it runs provers in the job market and collects the app share on the contracts it deploys, like anyone else. If the community ever wants a grant mechanism, miners can add one by signalling.</p>
|
||||
</section>
|
||||
|
|
|
|||
Loading…
Reference in a new issue