diff --git a/docs/fud-ledger-2.0.md b/docs/fud-ledger-2.0.md index 003050294..d5b340d8f 100644 --- a/docs/fud-ledger-2.0.md +++ b/docs/fud-ledger-2.0.md @@ -22,7 +22,7 @@ Pin: Architecture and product, sixth box (every served page carries the position Status: Open (8 October 2026): pass when the best supported cost and energy advantage of a re-optimised, programmable adversary sits inside the chosen competitiveness envelope, with its uncertainty published (D3). -Answer: The target is contestable mining, not chip destruction: a manufacturer with a profitable product is not the failure; an exclusive, durable advantage large enough to displace the accessible GPU fleet is. Two measured results already bound the design. The connected-state reorganisation was killed as a class because rearranging the same operations moves neither side (D2). The mixed FP32 branch was killed because deterministic FP32 costs the cards 15 to 26 percent energy per hash against a 10 percent budget and widens the chip's edge to 3.0x to 3.2x (measured cards, modelled chip). Both stay as regression controls. +Answer: The target is contestable mining, not chip destruction: a manufacturer with a profitable product is not the failure; an exclusive, durable advantage large enough to displace the accessible GPU fleet is. Two measured results already bound the design. The connected-state reorganisation was killed as a class because rearranging the same operations moves neither side (D2). The mixed FP32 branch was killed because deterministic FP32 costs the cards 15 to 26 percent energy per hash against a 10 percent budget and widens the chip's edge (measured cards, modelled chip; the figure paired against class v4 is withdrawn). Both stay as regression controls. Evidence: `docs/plans/igneum-2.0.md` (the objective, property 1; D1, the mixed FP32 kill; D2(a)); `docs/analysis/class-v6/connected-state.md`. diff --git a/site/claims.html b/site/claims.html index 363d10023..52f7317a6 100644 --- a/site/claims.html +++ b/site/claims.html @@ -249,7 +249,7 @@

Here are the limits, stated before anyone else states them.

Your card: pending

-

The devnet is being reset this morning, 9 October. A fresh install syncs once the reset completes. This line is re-read at 10:30 UK.

+

Before you install: a fresh sync from genesis needs 64 GB of memory today. 48 GB is the floor at this hour, and the number grows with the chain until the snapshot path ships (a fresh node reads about 30 GB of memory by DAA 44,000 and 35 to 40 GB at today’s tip, a gigabyte more every 17 minutes at one block a second; a 16 GB machine reaches DAA 7,000 to 8,000 about four minutes in and then swaps or is killed, a 32 GB machine about DAA 20,000). A smaller machine waits for the snapshot path, 2.0.3.1: its design is due by 12:30 today and the first served snapshot by 15:00; this note changes when it ships. The devnet was reset this morning, 9 October; a fresh install syncs from the reset chain.

What changed in 2.0.2 (Mac, 9 October). The public miner ships without remote execution; the fleet runs Igneum Miner Lab under its own signing root. Automatic updates are a choice at install and honoured. The recovery lock is named as recovery. A fresh install syncs through the epoch cuts and the node serves its proof records to every joiner. Windows and HiveOS stay on 2.0.1 until their builds are cut; 2.0.1 is the lowest supported version. DMG Igneum-Miner-2.0.2-5d53a591-1176efb9.dmg, sha256 66137cd8303356dacc2a0abc24088a88263ef81f3a85b16ba4b950cc6bcb806f, 46,002,244 bytes.

What changed in 2.0.1. An update never leaves mining off. The Cards tab is back as its own page. The first-block card shows once per address. The window names included, executed, proven and finalised. The node serves its manifest and the genesis state stream to every miner. The Mac build is unsigned tonight.

2.0.0 is withdrawn: its miner could not read this network’s block templates; every 2.0.0 install updates itself to 2.0.1.

diff --git a/site/ledger.html b/site/ledger.html index 2424713e9..4899df433 100644 --- a/site/ledger.html +++ b/site/ledger.html @@ -273,7 +273,7 @@ blockquote{margin:10px 0;padding:10px 14px;border-left:3px solid var(--line-2);c
GPU-friendly hashes always fall to chips. A specialist strips everything a GPU carries that the hash does not need.
Open 8 October 2026): pass when the best supported cost and energy advantage of a re-optimised, programmable adversary sits inside the chosen competitiveness envelope, with its uncertainty published (D3).
Pin The objective, property 1; D3 pass condition.
-
The answer as first written

The target is contestable mining, not chip destruction: a manufacturer with a profitable product is not the failure; an exclusive, durable advantage large enough to displace the accessible GPU fleet is. Two measured results already bound the design. The connected-state reorganisation was killed as a class because rearranging the same operations moves neither side (D2). The mixed FP32 branch was killed because deterministic FP32 costs the cards 15 to 26 percent energy per hash against a 10 percent budget and widens the chip's edge to 3.0x to 3.2x (measured cards, modelled chip). Both stay as regression controls.

+
The answer as first written

The target is contestable mining, not chip destruction: a manufacturer with a profitable product is not the failure; an exclusive, durable advantage large enough to displace the accessible GPU fleet is. Two measured results already bound the design. The connected-state reorganisation was killed as a class because rearranging the same operations moves neither side (D2). The mixed FP32 branch was killed because deterministic FP32 costs the cards 15 to 26 percent energy per hash against a 10 percent budget and widens the chip's edge (measured cards, modelled chip; the figure paired against class v4 is withdrawn). Both stay as regression controls.

R2

Ordinary operators will be priced out

8 October 2026
diff --git a/site/litepaper.html b/site/litepaper.html index f653511d7..6e2822a3a 100644 --- a/site/litepaper.html +++ b/site/litepaper.html @@ -463,7 +463,7 @@ body.all .pager{display:none} ContinuouslyThe dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. Each step is scored against the burden it puts on ordinary cards (Deliverable 3); growth is not counted on to retire a chipNo -

What carries the chip resistance is the scoring rule's result on the placed adversary rows, plus the economics, reported separately in the chip model below. Three properties feed it. Rotation is an option, not the defence. A new program every hour, drawn from the chain, its memory pattern with it, and rules that change on a schedule fixed at launch. These schedule changes defeat a chip wired for one datapath and need no human fork, but against a programmable chip that stores the dataset every drawn parameter is firmware, so the security argument does not rest on them. What meets that chip is the latency-shadow work (class v4) and the price per joule (the chip and economy analysis of 6 October 2026, section 5.4; ledger D3). It waits on memory, not maths. Every hash is a chain of random reads into a table too big for a chip to carry. Measured (8 October 2026; lane D’s family harness at the acceptance rule’s own 2^20 sample over 4,900 drawn eras, and the chained-cache pass’s reading of the night before): every hash executes 256 dependent 4-byte reads of the dataset under the class v6 object (the drawn program’s 16 load sites, run on both halves of the 64-register window, over 8 iterations; 128 on the classes before it), and each read lands anywhere in the 1 GiB dataset at genesis (every load site reads the whole dataset, a half or a quarter at a drawn offset), so the card pays a full memory latency per read; the reads land across the whole dataset and the distinct-index floor holds at 0.995 on every accepted program; about half of epochs carry one load site whose address bit at the era’s stride rotation is biased, which prices about 1.6 percent of a hash’s reads to a chip storing half the dataset and nothing to a chip storing all of it; the next class folds the product’s low bits before the rotation, so no era lands a biased bit on an address bit. The wait is the same physics for everyone. Miners hold the switch. Spare defences are written into the rules, switched off. A miner signal turns one on, at the class-change threshold: miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. No fork.

+

What carries the chip resistance is the scoring rule's result on the placed adversary rows, plus the economics, reported separately in the chip model below. Three properties feed it. Rotation is an option, not the defence. A new program every hour, drawn from the chain, its memory pattern with it, and rules that change on a schedule fixed at launch. These schedule changes defeat a chip wired for one datapath and need no human fork, but against a programmable chip that stores the dataset every drawn parameter is firmware, so the security argument does not rest on them. What meets that chip is the price per joule (the chip and economy analysis of 6 October 2026, section 5.4; ledger D3). It waits on memory, not maths. Every hash is a chain of random reads into a table too big for a chip to carry. Measured (8 October 2026; lane D’s family harness at the acceptance rule’s own 2^20 sample over 4,900 drawn eras, and the chained-cache pass’s reading of the night before): every hash executes 256 dependent 4-byte reads of the dataset under the class v6 object (the drawn program’s 16 load sites, run on both halves of the 64-register window, over 8 iterations; 128 on the classes before it), and each read lands anywhere in the 1 GiB dataset at genesis (every load site reads the whole dataset, a half or a quarter at a drawn offset), so the card pays a full memory latency per read; the reads land across the whole dataset and the distinct-index floor holds at 0.995 on every accepted program; about half of epochs carry one load site whose address bit at the era’s stride rotation is biased, which prices about 1.6 percent of a hash’s reads to a chip storing half the dataset and nothing to a chip storing all of it; the next class folds the product’s low bits before the rotation, so no era lands a biased bit on an address bit. The wait is the same physics for everyone. Miners hold the switch. Spare defences are written into the rules, switched off. A miner signal turns one on, at the class-change threshold: miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. No fork.

The work that waits can grow. Class v4 adds a block of latency-shadow arithmetic to every hash, about 100,000 integer operations that run while the memory reads are in flight, so a chip that stores the whole dataset still has to pay for a core. That size sits on a ladder fixed at genesis, six rungs from about 100,000 to about 1,000,000 operations, and it moves one rung at a time only when 90 percent of blue blocks in each of seven consecutive days ask for it; it can never move two rungs inside a week and never past a rung the reference verifier cannot check under 10 ms with its sibling thread busy (measured on the build server, 6 October 2026: the first three rungs pass at 8.8, 8.9 and 9.2 ms, the fourth misses by 0.08 ms on a loaded box and stays out until a quiet re-measurement, the two doublings are out at 12.4 and 15.0 ms). What it buys against a chip is scored under the rule in the chip model below. What it costs, per rung, is measured too: the Apple tier gives up 3 points of rate at the first step and 6 more at the second, the RTX 5090 nothing until the second; so the miners who pay for a step are the ones who take it.

The chip model

Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling estimates a 1.5x to 3.1x energy-efficiency advantage for the specialised designs assessed as complete machines against the GPU tier, from a board on commodity DRAM at 1.5x to an SRAM-store die at 3.1x (1.5x to 2.3x on the GPU's own node). For the board on commodity DRAM the two independent chip models agree after placement: 1.5x to 2.1x as a complete machine and 2.0x to 2.9x for the board alone on the GPU’s own node; a node ahead 1.8x to 2.4x and 2.45x to 3.3x (placed and routed on ASAP7, both lanes, the node scaling claimed, the machine terms modelled; the 2.9x end is the resizer-downsized floor of the placed 32-lane comparator, not a point, until the placed core32 lands). The standard’s P04 target reads FAIL at both ends, served as such. The standard’s P04 target as approved: R_E at most 1.5 on the same node and one node ahead; today’s placed bracket reads against it as a FAIL to work against. The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment.

@@ -483,7 +483,7 @@ body.all .pager{display:none} Economic resistanceWhether a chip gets built depends on development cost, deployment economics and productive hardware lifetime. The first cut of the profitability surface: the price at which a project pays scales as the project cost over its share of the chain times its discounted life, and moves by under 5 percent with the per-joule edge; a fixed-lane chip under rotation needs 4x the price a programmable one needs. No threshold is the headline: the five-year coexistence model (Deliverable 4; its first run is docs/analysis/class-v6/coexistence-model.md, every row modelled) replaces any capex wall: the DRAM board passes six of its seven success conditions at a one to three year life; the SRAM die fails four conditions at its reconciled machine cost; the larger half of a chip's edge is capital cost per accepted hash, not joules. The result, as the model words it: A specialised supplier may earn a normal return; ordinary GPUs remain sufficiently close in total cost, widely obtainable and useful outside mining that new operators can still compete. On today's modelled rows that holds for the chip anyone can build, a stored-dataset board on commodity DRAM, at a productive life of one to three years: its cost per accepted unit of work sits within the range of the best GPU owner and entrant, it passes six of the seven conditions (a third of the network in boards now costs less than a year's revenue at the final hardware price), and a fleet of it holds a minority of the network with GPU entrants still setting the price. For the SRAM-store die the outcome turns on its hardware cost per unit of work, not its energy advantage: at the reconciled machine cost, set by the power train and the shadow core rather than the die, it fails the cost, hardware, fleet and margin conditions at every point of the band, a modest fleet holds about two fifths of a growing network and three fifths of a flat one on arrival and takes every flat or shrinking network within five years, and the only coexistence-shaped outcome is private supply in a growing network; what holds it is the investment decision, since its economics are project economics. A third design, a DRAM board with the hottest half of the dataset in on-board SRAM, sits between the two: it coexists only in a growing network at cheap GPU electricity and fails the cost conditions in a flat or shrinking one, and the dataset's size floor is a real lever on it where it was none on the SRAM die. What holds the die is the investment decision, not the hash; every chip figure here is modelled, not measured, and the chip's hardware cost per unit of work is approximate within 2x. The model holds under every market structure for the DRAM board (private supply, hardware sales, multiple suppliers, with no single supplier above a quarter of the network), and the SRAM die under none but private supply in a growing network; the thresholds live in the model's sensitivity workbook (docs/analysis/class-v6/coexistence-workbook.md), never on a page. A failure, reported as found: ECO-05, the standard’s coexistence sweep, was run on a register frozen before any result against a sourced revenue reference of USD 31.65 million a year of miner revenue (Ethereum Classic’s trailing year at its current era 6 reward) and FAILS the envelope as the chain stands. Of sixteen revenue and tariff worlds (a quarter, one, four and ten times the reference; electricity at 3, 10, 25 and 40 cents per kilowatt-hour) one sustains new entry across two vendors on the measured cards, ten times the reference at 3 cents (about USD 316 million a year), and a second, ten times the reference at 10 cents, on the RX 7600’s modelled efficiency point, which the metered row due in the morning keeps at or below 5.4 microjoules per hash and takes away above about 5.6; the cause is that on this hash the measured AMD and Intel cards cost four to six times a Blackwell card per joule and never earn a new entrant’s purchase back at list price below those worlds; the verdict is FAIL either way; in those worlds no specialised design sits inside the envelope against the whole cohort (the board on commodity DRAM is within the envelope only against the best Blackwell card, the die and the hybrid against no card of today’s), and the quarter-reference worlds at 25 and 40 cents are collapse worlds with no rational profitable operator. What moves the result is the specialist’s hardware cost per unit of work, the honest cards’ own efficiency on this hash, above all the AMD and Intel cards’ energy, and the dataset’s size floor; not a smaller network, a higher token price or any chip’s death. Reported as found; the register, the full result cube and the model are published for independent reproduction. (Labels: the register frozen at 18:37 UK on 8 October 2026, the reference corrected by a second public read and the run repeated with the verdict unchanged, the cube MODELLED on measured card rows, two cohort rows BLOCKED, the RX 7600’s knee and the Arc’s watts, their measurement running tonight; the registry row ECO-05 on /acceptance; the results file docs/analysis/class-v6/eco-05-results.md.)MODELLED, the coexistence model's first run, 8 October 2026 Response capabilityRotation is an optional improvement, not the mechanism. A passed rotation boundary proves the rotation works, not that hardware dies. The schedule: a new program every hour, a parameter era every week, a family epoch every 180 days, an emergency vote when miners call one. Rotation costs a chip versatility, not life: the family bank is firmware plus about 43 percent of core cells, and no transition carries an obsolescence credit (modelled).measured per boundary, 8 October 2026; the family-bank cost modelled, 8 October 2026 -

What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). The devnet runs class v4 from its first block. Classes rotate on findings and at least yearly; a class change is a release activated by block height. Class v5 is built to cross by height; its dataset keyed by the chain's own state is under evaluation (Deliverable 3) and is not counted as a defence until justified. Class v6 is the design in progress (opened 8 October 2026), with four layers as its spine: per-era draws of the parameters a release now fixes, a dataset whose size tracks the chain state (under evaluation, Deliverable 3), scheduled family epochs by height, and the acceptance floor generalised to every era’s draw. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet.

+

What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). The devnet runs class v5 from its first block, the class v4 latency shadow inside it (the release manifest’s class row). Classes rotate on findings and at least yearly; a class change is a release activated by block height. Class v5 is built to cross by height; its dataset keyed by the chain's own state is under evaluation (Deliverable 3) and is not counted as a defence until justified. Class v6 is the design in progress (opened 8 October 2026), with four layers as its spine: per-era draws of the parameters a release now fixes, a dataset whose size tracks the chain state (under evaluation, Deliverable 3), scheduled family epochs by height, and the acceptance floor generalised to every era’s draw. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet.

No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the economics and the response capability, each separately, and each carries its label. The precedents, as sourced (nameplate and community tables, about 20 percent either way; every figure with its URL and date in the close): Monero has run on RandomX since November 2019, its rules stable since then and its programs varying per hash; one chip shipped against it, Bitmain’s Antminer X5 (September 2023), 46 months after the fork, at 6.37 J per kH at the wall against a stated CPU measurement, an observed comparison, not a ceiling. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. RandomX v2 was released on 25 March 2026 with its mainnet activation pending. Ethash ran 36 months to a first chip worse than a GPU; the iPollo V2H reads about 14x today. Kaspa ran 21 months to its first chip, at 167x to 725x. The commodity cohort Igneum protects is the discrete-GPU population; the Apple row is reported beside it, never as the headline.

The reference population and the cost per accepted unit of work. The reference population is the discrete-GPU classes the network protects, from the RTX 5090 to the RX 7600 8 GB and the Arc B580, with Apple reported beside them; for each the table gives the cost per accepted unit of work for an existing owner (power, wear, fees, over accepted work) and for a new entrant (purchase at list and street price, two years of operation, resale), at three electricity prices, with every figure labelled measured or modelled. On today’s rows the cheapest honest owner is a 16 GB Blackwell card at its efficiency point and the cheapest entrant the same card at list price; the specialised board on commodity DRAM costs more per accepted unit than any owner and sits between the entrant’s list and street figures. The chip rows carry “modelled, hardware cost approximate within 2x”; no thresholds, no chip percentages (the table, floor lane 3 for the research lane, 8 October 2026).

The disclosure prize. A placed or measured adversarial implementation that beats the served bracket under the one acceptance rule, or a reproduced shortcut in the served kit, earns the disclosure prize; a confirmation does not. The terms are on that page; the amount is the founder’s and is served when set.

@@ -854,7 +854,7 @@ body.all .pager{display:none}

Here are the limits, stated before anyone else states them.