Merge class-v6-history 49d7ff46 into master (gate: green on 49d7ff46, recorded by tools/ci/pre-push.sh; landed on the build mirror)

This commit is contained in:
igneum-labs 2026-10-08 10:26:13 +00:00
commit 95c3a37483

View file

@ -0,0 +1,300 @@
# Class v6 research lane A, history: every ASIC-resistant proof of work, how it fell or held, and what that binds on the four layers
8 October 2026, branch `class-v6-history`, the Counter ASIC coordinator's history lane. The founder's word at 11:1x UK: class v6 is declared with four layers as its spine, and the research opens "see if anything can be optimised, added or invented". This file extends and corrects `docs/analysis/asic-resistance-history.md` (5 October 2026, the deep dive: 31 rows, 24 papers, ten lessons, seven ranked additions); it does not repeat that file's rows. What is new here: the exact MECHANISM of every chip (what it specialised: the memory, the hash core, the instruction mix, the parameter fixity), what each design missed, the timeline from announcement to chip to response, and for each one the mapping to class v6's four layers with "does v6 close it" in one sentence and one number. Every figure about another chain cites a URL with the date it was read, or is labelled approximate. Every Igneum figure names the repo file. Reading public research is in-house; nothing is paid or asked of anyone outside.
First cut landed before 15:00 UK on 8 October (the table, the mechanisms, the three lessons); the full report by 09:00 UK on 9 October. A line goes to the coordinator and to the synthesis lane at each landing.
## 0. One page
**The four layers, as declared, against the history's chip classes.** Every chip that ever beat a resistant hash belongs to one of five classes; the table says which layer of v6 answers each class, and with what number. "Closes" means the chip's measured or claimed edge falls under 2x per joule by a mechanism the layer supplies; "does not close" means the layer does not touch the chip's edge, and the number stands.
| Chip class (the rows of section 1 it covers) | What the chip specialised | Its best measured edge | Which v6 layer answers it | Does v6 close it | The number after v6 |
|---|---|---|---|---|---|
| A. Fixed-function pipeline on a compute-bound hash (X11, Blake-256, Blake2b, Blake2s, kHeavyHash, Eaglesong, Blake3, SHA512/256d, NexaPow, X16R's FPGA) | the hash's round function unrolled in silicon; the instruction mix fixed at genesis | 33x to 1,280x per joule (Antminer KA3, D3, KS5 Pro) | layers 1 and 3 (the op mix, program length and families drawn or unlocked per era; already closed since class v2 by the per-epoch random program) | yes, and it was already closed: a per-epoch program has no round function to unroll | 0 of 128 loads and 0 of 512 program ops are a fixed function; what remains is class E |
| B. SRAM-scale memory (Scrypt's 128 KB, CryptoNight's 2 MB, Lyra2REv2's sponge, Cuckatoo's edge bitmap, Equihash's 144 MB) | the hash's whole working set on die or across a few dies, with a time-memory trade-off the designer had not drawn | 19x to 1,100x (Scrypt), 40x to 50x (CryptoNight X3), 12x to 100x (Equihash Z9 to Z15), 4x (Cuckatoo G1) | layer 2 (the dataset above any SRAM die, growing with chain state with a floor; the 256 MiB cache growing with it) | yes: the recompute chip that holds the cache on die reads 0.92x at the op budget and 1.86x per joule, and the cache's size forces it onto a 7 nm or better node | `chip-model-v3.md` section 2 and 5.4: 0.31x bare, 0.92x with the 3x factor, 1.86x per joule at f = 0; the curve from f = 0 to 1 is monotone and the partial-store chip is worse than both ends |
| C. The memory system without the GPU (the Ethash chips: Linzhi Phoenix, Jasminer X4, Antminer E9; the f = 1 chip of the model) | a controller and PHY for the same DRAM the card carries, a 32-byte atom per read, no shader, no scheduler, no clock tree; 55 W of memory without the 271 W of GPU | 2.1x to 4.8x per joule measured (Ethash, 2020 to 2022); 5.1x (GDDR7) to 7.5x (one HBM3 stack) modelled for Igneum at zero premium | none of the four directly: every per-era draw is firmware to a chip that stores the dataset; layer 2 only when the dataset passes the chip's board | **NO.** The f = 1 chip keeps 5.1x per joule on GDDR7 at zero premium and 2.1x with the class v4 shadow at k = 1; v6's draws move neither figure. What moves it is the honest card's own joules (the operating point, 3.6x at the 1,300 MHz knee) and the shadow's premium | 5.1x / 3.6x / 2.1x (zero premium unlocked / knee / knee with the shadow at k = 1), `counter-asic-4-research.md` sections 0 and 20.4; the chip's USD 2.8 per MH/s against the card's 14.7 |
| D. The firmware-survivable chip against periodic change (Monero's chips across four forks, Vorick's "survives forks at under a 5x hit", the X16R FPGA, the Equihash chip "able to follow parameter forks") | a programmable sequencer over the hash's op set; the per-block or per-fork change read as a configuration | chips back at 85 percent of Monero's hashrate four months after the v8 fork; 1.3x on X16R | layers 1 and 3 are the automatic form of the change those chains made by hand; they cost no governance event | partly: v6 closes the GOVERNANCE failure (no fork, no reset of the hashrate to a rentable size) and taxes die area for the reserve; it does not close the chip, because a reserve and a draw band readable at genesis are built in from day one | the draw's cost to the chip is a recompile per epoch and a new dataset mapping per era; the number is the "GPU without graphics" of ledger M1, which is class C's chip with a sequencer beside it: 5.1x less the shadow's k |
| E. The hot set and the steered address (Kik's 64-bit seed on ProgPoW, Dinur-Nadler on MTP, AP-F8-1 on class v4, the weak-day MUL draw) | a small SRAM serving the reads a biased draw or a cooperating node concentrates | 1.067x at v4's ceiling (0.52 to 4.6 percent of reads on 0.1 percent of items); a memory skip on ProgPoW 0.9.3; MTP from 2 GB to under 1 MB | layer 4 (the (c''') floor and the F8-form uniformity test generalised to every era's draw, with a redraw on failure) | yes, for the class the test models: the floor at 0.995 refuses every live hot set the in-house pass found (nine, 0.9809 to 0.9919) at 0.7 percent of candidates | `docs/spec/01-lottery-hash.md` 1.4.7.2 (class v5); the open residue is the shadow-written concentrations at 0.9992 to 0.9997, worth about 1.0004x to a chip |
**The three lessons that bind on v6** (section 3 has the evidence):
1. **The chip that stores the dataset is firmware-immune to every draw; only joules and memory growth move it.** Every per-era parameter (mixer rounds, op weights, read width, program length, shadow placement) and every family epoch is read by the f = 1 chip's sequencer as a configuration, as Monero's chips read four forks and X16R's FPGA read the per-block order. The number v6 inherits is 5.1x per joule at zero premium (2.1x with the shadow at k = 1), and the lever is the honest card's operating point and the shadow's premium, not the draw.
2. **Automatic change beats the human fork only where it costs the chip a redesign, and the one parameter that does is the memory.** Grin's six-monthly tweaks held because each was a new algorithm the lane was scheduled to retire; Monero's forks lost on the second lap; Ethash's DAG growth is the one scheduled change in the record that killed a shipped chip (the E3, when the DAG passed its 4 GB of DDR3). Layer 2 is that lesson made a rule, and its rate decides everything: at 2 GiB plus 0.5 GiB a year a 32 GB chip board outlives the chain, so layer 2 as declared ages out the honest 8 GB card before any chip unless the floor is set against DRAM cost per gigabyte, not against chain state.
3. **A steered or biased address pattern is always found after launch unless the test lives in the acceptance rule, and every new draw needs its own null.** ProgPoW's seed, MTP's blocks and class v4's lossy sources were the same attack three times; layer 4 puts the test where it must be, and its cost is one census per era draw on the node (2.2 s per candidate at 2^20 today) with the null re-derived for every drawn parameter, because the window model that defines "uniform" changes with the read width and the program length.
**What the history says to add** (section 5): the issuance clock and the share-pattern detector (unchanged from the 5 October ranking, still unbuilt); a layer 2 floor stated in DRAM dollars; the read width kept out of the era draw unless a width other than 4 bytes is measured latency-bound on every vendor; the reserve ordered by what a sequencer chip cannot fold into firmware.
## 1. The chips, one row per mechanism
Columns: the hash; the chip (vendor, model); the mechanism (what it specialised); what the design missed; the timeline (hash live, to the chip, to the response); the v6 layer that answers it; does v6 close it; the number (the chip's measured or claimed per-joule edge, and what the layer leaves). Every ratio is arithmetic on the cited rate and watt figures of the chip and the best consumer GPU of its year, approximate by construction; section 2 carries the sources. "Closed at v2" means the per-epoch random program already removed the mechanism and v6 inherits it.
| Hash (chain) | Chip | Mechanism: what it specialised | What the design missed | Timeline | v6 layer | Closed by v6 | The number |
|---|---|---|---|---|---|---|---|
| Ethash (Ethereum) | Bitmain Antminer E3 | 18 chips with 4 GB of commodity DDR3; "a memory interface connected to a small compute engine" | the hash needs only a memory interface; and the chip's memory was under-sized | live Jul 2015; chip announced Apr 2018, shipped Jul 2018; died by DAG growth Mar to Oct 2020 | 2 (the only layer that reached it) | class C: no | 1.0x to 1.1x per joule; the DAG passed its 4 GB at 20 to 27 months |
| Ethash | Innosilicon A10, A10 Pro, A11 Pro | the same with faster, larger DRAM (6 to 8 GB) | as above | Jul 2018 to Dec 2021 | none | no | 1.4x to 2.5x |
| Ethash | Linzhi Phoenix (E1400) | 64 compute units and 72 mixers per board beside 4.4 GB of "decentralized memory inside its ASIC"; sized to the DAG | memory energy per bit is the whole cost; many small memories by many small cores cut it | announced Sep 2018; tapeout Sep 2019; samples Dec 2020; no mass production | none | no | 2.1x to 2.2x |
| Ethash | Jasminer X4 (Sunlune) | DRAM dies hybrid-bonded (wafer-to-wafer DBI) onto a 40/45 nm logic die, 5 GB per unit, 40 chips per server | off-package DRAM at 3 to 4 pJ per bit was the cap; bonding takes it under 1 | Jun 2021 chip; Oct 2021 ship; the Merge 11 months later | none | no | 5.1x (about 7.3 pJ per bit all in) |
| Ethash | Bitmain E9, E9 Pro | conventional, 6 to 7 GB | as the E3, four years of DRAM later | Jul 2022 (8 weeks before the Merge); Feb 2023 | none | no | 3.0x, 4.1x |
| ProgPoW (never on Ethereum; KawPow, FiroPoW, ProgPowZ, Quai) | none; Linzhi claimed 3x to 8x with no derivation; one academic VU35P FPGA at 5.6 MH/s | a sequencer over eleven ops reads the per-period program as configuration (unbuilt); the on-die cache chip priced at "<< 0.1x" energy (unbuilt) | the light-evaluation chip was left as a suggestion; a 64-bit seed (Kik) | EIP May 2018; audits Sep 2019; exploit Mar 2020; dead Mar 2020; no chip on any adopter in 6 years | 1, 3 (the period made an era draw), 4 (the seed class) | class D and E yes; the Rao chip is class C, no | claimed 1.1x to 1.2x for the compute chip; the memory-system chip never priced; Igneum's reads 5.1x |
| RandomX (Monero) | Bitmain Antminer X5 | many RISC-V chips on a board over commodity DRAM: an in-order machine for a fixed VM spec; insides never published | CFROUND's cost on x86, a scratchpad-only AES circuit, the latency slack of a fixed 256-instruction program (v2's own list) | live Nov 2019; private mining from about 2021; X5 Sep 2023; X9 announced Dec 2025 and withdrawn May 2026 (zero shipped); v2 released Mar 2026, activation pending | 1 (program length and op mix drawn, which v2 had to fork to change) | class D: yes for the class; the gap itself has no GPU analogue | 1.46x (X5, measured); 3.8x (X9, claimed, never shipped); 5.4x (Pinecone R1X, claimed, undelivered) |
| CryptoNight (Monero) | Bitmain Antminer X3 (180 x BM1700); Baikal Giant N; secret chips from early 2017 | one or two 2 MB scratchpads in on-die SRAM with a hardware AES round per chip (inference from 1.2 kH/s at 2.6 W per chip) | the working set was a 2014 L3, which is a die | live Apr 2014; secret chips about 33 months; X3 announced at 47 and bricked by the v7 fork before delivery; chips back inside 4 months of v8; none in CN-R's 9 months | 2 (the dataset above any die); 1 and 3 (CN-R's per-block program is Igneum's per-epoch one) | yes | 40x (X3 against a Vega 64); Igneum's f = 0 chip 1.86x per joule |
| Cuckatoo31 (Grin) | Obelisk GRN1 (cancelled) | one TSMC 16 nm die with 512 MiB of SRAM holding the node bits, lean mining; 150 GPS at 800 W per chip | the resource was SRAM size at 320 MB, and a die was designed for it | hash live Jan 2019; announced Jan 2019; sold Apr; cancelled Jul 2019 | 2 | yes (closed at v3) | 50x planned; the 2025 bounty: memory trades for time, not energy |
| Cuckatoo32 (Grin) | iPollo G1 (30 x 12 nm chips) | node bits on die, the 512 MB edge bitmap in serial DRAM (the design's geometry; the G1's own split unpublished) | half the working set stayed in DRAM | Dec 2020, 23 months | 2 | yes | 3x |
| Equihash 200,9 (Zcash) | Bitmain Z9 mini, Z9 (BM1740); A9; Z11; Z15 Pro | the whole 144 MB working set on one die ("about 128 MB", eDRAM or SRAM); the Fudan NDSS 2019 design: an on-die linear sorter with the lists in off-chip DDR4, parameter-independent | the 1,000x halving penalty had no proof; 144 MB fit a die; a chip was designed to follow any (n, k) | live Oct 2016; secret chips before May 2018; Z9 mini at 18 months; Z15 Pro at 80 | 2 (a 2 GiB set is not a die); the parameter-following chip is layer 1's warning | yes by layer 2 | 12x (Z9 mini) to 110x (Z15 Pro); the Fudan design 13x in simulation |
| Scrypt (Litecoin) | Innosilicon A2; KnC Titan; Antminer L3+ (BM1485); L7 (BM1489) | one 128 KB scratchpad of on-die SRAM per core, 12 cores per 28 nm chip (L3+), 7 nm with 480 chips (L7); Percival's own lookup gap (half the memory for 25 percent more work) | the scratchpad was a 2011 cache; the time-memory trade favoured the chip at 2x to 4x by the designer's note | live Oct 2011; A2 Apr 2014 (30 months); L3+ Jun 2017; L7 Nov 2021 | 2 | yes | 70x (A2) to 1,300x (L7); Igneum's f = 0 chip 1.86x |
| Scrypt-N (Vertcoin 2014) | none; dropped pre-emptively | an automatic N doubling a chip follows with more SRAM or a wider lookup gap | public and slow growth sizes the chip for years | Jan 2014 to Dec 2014 | 2 (the precedent) | n/a | no chip shipped |
| Lyra2REv2 (Vertcoin) | FPGA bitstreams (2018), then Dayun Zig Z1 | a sponge of about 200 KB per core on die (approximate); 28 nm | SRAM-scale memory inside a hash chain | live Aug 2015; FPGA 2018; Z1 Sep 2018 (37 months); fork Feb 2019 | 2 | yes | 20x |
| X16R (Ravencoin) | CVP-13 FPGA bitstreams; OW1 and SKC Turing R1 | sixteen fixed cores with per-block routing | the draw changed the order, not the hardware | live Jan 2018; FPGA named Sep 2018; 45 percent of blocks by Jul 2019; fork Oct 2019; chips "evident" again Jan 2020 | 1 (the warning) | the fixed-function lane closed at v2; the draw is governance | 0.75x (OW1) to 5x (R1) |
| MTP, Argon2d (Zcoin) | none; Dinur-Nadler's attack before launch | the prover steers the data-dependent addresses into under 1 MB at a 170x penalty | the attacker controlled the memory's contents | 2017 attack; live Dec 2018; replaced Oct 2021 | 4 | yes (the day key is a VDF of chain state; the floor refuses hot sets) | 2 GB to under 1 MB; Igneum's residue about 1.0004x |
| Yescrypt, yespower | none | L2-latency-bound sequential work; small prizes | n/a | 2014 on | 2 | n/a | no chip |
| KawPow, Autolykos v2, Octopus, Verthash, FishHash | none | DRAM-scale random reads on small prizes | untested at a prize that pays for a controller project | 2020 to 2024 | 2 | class C: not tested | no chip; the Ethash record is their test |
| kHeavyHash (Kaspa) | IceRiver KS0 to KS5L; Antminer KS3, KS5 Pro | a fixed 64 x 64 nibble matrix pipeline | compute with a matrix in it is the cheapest silicon there is | live Nov 2021; KS0 Sep 2023 (22 months); GPU share gone by late 2023 | closed at v2; the mm8 reserve's warning | yes | 170x to 720x |
| Eaglesong (Nervos) | Toddminer C1; Antminer K5, K7 | a fixed sponge pipeline | compute | 4 months | closed at v2 | yes | about 100x |
| Blake3 (Alephium); Blake2s (Kadena); Blake-256 (Decred); Blake2b (Sia); X11 (Dash); SHA512/256d (Radiant) | the 5 October file's rows | fixed pipelines | compute | 4 to 31 months | closed at v2 | yes | 33x to 6,500x |
| NexaPow (Nexa) | DragonBall A21 | a secp256k1 Schnorr signature per nonce in hardware | a wide multiplier chain is already what the GPU does well | live 2023; chip Dec 2024 | closed at v2 | yes | 2.2x: the one compute row where the chip's edge stayed small |
What the table says, sorted by class: class A (fixed pipelines) 33x to 6,500x, closed at v2; class B (SRAM-scale sets) 12x to 1,300x, closed at v3 by the dataset and the drawn curve; class C (the memory system) 1.0x to 5.1x measured on Ethash, modelled 5.1x to 9.2x for Igneum, NOT closed by any layer; class D (firmware-survivable sequencers) 0.75x to 5x on the program side, closed as governance and open as a chip; class E (steered addresses) closed by layer 4 for the class it models.
## 2. The chips, in depth
One section per proof of work. Each carries the mechanism, the miss, the timeline, the layer mapping and the number. Where a lane's return says "not found" the row says so.
### 2.1 Ethash (Ethereum, July 2015): the E3, the Innosilicon line, Linzhi, Jasminer and the E9
**The mechanism of the hash.** A DAG of 1 GB growing 8 MB per epoch of 30,000 blocks (about 0.7 GB a year), 64 random 128-byte reads per hash mixed by FNV, keccak at each end; bandwidth-bound by design. EIP-1057 states the miss in one sentence: Ethash "requires external memory due to the large size of the DAG. However that is all that it requires - there is minimal compute ... a custom ASIC could remove most of the complexity, and power, of a GPU and be just a memory interface connected to a small compute engine" (https://eips.ethereum.org/EIPS/eip-1057, read 8 October 2026).
**The chips, and what each specialised.**
| Chip | Announced, shipped | The mechanism, as far as any source states it | MH/s, W, MH per joule | Against the best GPU of its year (derived, approximate) | Source (read 8 October 2026) |
|---|---|---|---|---|---|
| Bitmain Antminer E3 | leaked March 2018, announced 3 to 4 April 2018 at USD 800 (five per customer), shipped 16 to 31 July 2018; later batches USD 1,800 | 18 Ethash chips on three boards with 4 GB of commodity DDR3; chip, node, controller and read width never published; Bitmain's own support called it "a 4G video card" whose DDR "is up to the upper limit"; Rao's audit classes it as the conventional strategy (compute in silicon, memory off chip) | 180 claimed, 190 to 200 shipped, at 800 W: 0.24 MH/J | 1.0x to 1.1x against a tuned GTX 1080 Ti (45 MH/s at about 200 W, 0.225); under Rao's best overclocked 2019 GPU (0.40) | https://cryptoslate.com/bitmain-e3-asic-ethereum-miner/ ; https://2miners.com/blog/asic-miners-for-ethereum-antminer-e3-vs-innosilicon-a10-eth-master-comparison/ ; https://coingeek.com/memory-limitations-prompt-bitmain-antminer-e3-to-halt-etc-support/ ; https://www.kryptex.com/en/hardware/nvidia-gtx-1080-ti/reviews |
| Innosilicon A10 ETHMaster, A10 Pro (6 GB), A10 Pro+ (7 GB), A11 Pro (8 GB) | A10 announced 23 July 2018 at 365, 432 and 485 MH/s (USD 3,800 to 5,000); A10 Pro June 2020; A10 Pro+ January 2021; A11 Pro presold March 2021 at 2,000 MH/s and 2,500 W, shipped December 2021 at 1,500 MH/s and 2,350 W ("20 percent less efficient"; broker quotes about USD 27,000) | the same conventional chip with a larger and faster memory system; the DRAM type is not stated on any page read (GDDR6 is the trade's assumption, approximate); node and read width not found | A10 485 at 850 W: 0.57; A10 Pro 500 at 860: 0.58; A10 Pro+ 750 at 1,350: 0.56; A11 Pro 1,500 at 2,350: 0.64 (0.80 claimed) | A10 2.5x against the 1080 Ti; A10 Pro 1.4x and A11 Pro 1.6x (2.0x claimed) against a tuned RTX 3090 (120 MH/s at about 295 W, 0.41) | https://www.criptonoticias.com/mineria/nuevo-minero-asic-innosilicon-procesa-485-mh-ethereum ; https://www.theblock.co/post/125871/innosilicon-ethereum-miner-a11-pos ; https://whattomine.com/coins/151-eth-ethash/asics |
| Linzhi Phoenix (E1400) | announced 13 to 14 September 2018 by Chen Min (ex-Canaan) at 1,400 MH/s and 1 kW for April 2019; planned tapeout December 2018, actual September 2019; sample rollout 21 December 2020; no mass production; price never published; the company now "studying new opportunities" | two E1400 boards, each 64 compute units and 72 "mixers" with 4.4 GB of "decentralized memory inside its ASIC design" (The Block); the DRAM type never published (one 2019 forum post says an interposer and stacked HBM dies, unverified); the 4.4 GB sized to the DAG rather than to a commodity 6 or 8 GB, which reads as memory sized per chip (inference); Linzhi claimed a ProgPoW chip would reach 3x to 8x | 2,600 claimed, 2,733 measured by F2Pool, at about 3,000 W: 0.87 to 0.91 | 2.1x to 2.2x against the tuned 3090 | https://www.theblock.co/post/88622/questions-new-ethash-asic-ethereum ; https://www.coindesk.com/tech/2020/12/21/linzhi-begins-rollout-of-long-awaited-ethereum-miner-phoenix ; https://bitcoinmagazine.com/business/new-mining-manufacturer-linzhi-announces-ethereum-asic-miner ; https://linzhi.io/ ; https://github.com/Souptacular/linzhi |
| Jasminer X4 (Sunlune) | chip announced 6 June 2021; X4 server announced 11 October 2021, first batch shipped 29 October 2021; launch price not found (USD 497 used today) | **the only Ethash chip that moved the memory**: TechInsights found "the first ever DRAM-to-Logic hybrid-bonding" (wafer-to-wafer DBI), DRAM dies bonded face to face onto a 32 mm by 21 mm logic die on XMC's planar 40/45 nm node; Jasminer's words: "3DIC technology, by integrating the data storage unit and the computing unit on the same chip"; 5 GB per unit, 40 chips per X4 server; the DRAM vendor, capacity per die and node not found | 2,500 at 1,200 W: 2.08 (the X4-1U 520 at 240 W: 2.17) | 5.1x against the tuned 3090; a physics check: 64 reads of 128 bytes is 65,536 bits a hash, so 2.08 MH/J is about 7.3 pJ per bit all in, under any off-package DRAM | https://www.techinsights.com/ko/node/51986 ; https://www.techinsights.com/ko/node/52149 ; https://semiconductor-digest.com/?p=22931 ; https://miningnow.com/asic-miner/jasminer-x4-2500mh-s/ |
| Bitmain Antminer E9, E9 Pro | teased 27 April 2021 as "3 GH/s, the work of 32 GPUs"; shipped July 2022 at 2.4 GH/s, eight weeks before the Merge; E9 Pro February 2023, Classic only | conventional off-chip DRAM at larger scale: E9 (model 240-E) 6 GB in six bins 2,100 to 2,400 MH/s; E9 Pro (260-E) 7 GB; memory type not found on any page read; no teardown | E9 2,400 at 1,920 W: 1.25; E9 Pro 3,680 at 2,200: 1.67 | 3.0x and 4.1x against the tuned 3090 | https://d-central.tech/antminer-e9-family/ ; https://www.asicminervalue.com/miners/bitmain/antminer-e9-2-4gh ; https://www.coindesk.com/tech/2021/04/27/bitmain-to-release-antminer-e9-asic-for-ethereum-mining |
**Why the cap sits at 2x to 5x.** Rao's audit (6 September 2019): every DAG read is random at about 40 ns of latency "completely independent of the memory bandwidth or the computation engine"; "typical DRAM energy dissipation is 3 to 4 pJ per bit" and "the energy expended to move data from DRAM to compute are the same for GPU or ASIC", so the shipping chips showed "about 1.6x hashrate per watt over GPUs" (E3 0.24, A10 0.57, the best overclocked GPU 0.40 MH/W in his table); integrating memory with logic cuts the movement energy "much more than 10x" to "under 0.3 pJ per bit", "the looming threat" (https://github.com/ethcatherders/progpow-audit, the PDF's text, read 8 October 2026). Ren and Devadas (TCC 2017) give the bound: memory hardness bounds area, not energy; the energy of a memory access is comparable on a chip and a CPU, so bandwidth hardness is the only energy lever (https://eprint.iacr.org/2017/225). The derived ladder at 65,536 bits a hash: pure memory energy caps Ethash at about 0.76 MH/J on DDR3, 2.8 on GDDR6 and 3.9 on HBM2 (O'Connor et al., MICRO 2017: HBM2 3.92 to 3.97 pJ per bit, GDDR5 14.0); the shipped chips sit at 0.24 (E3), 0.6 (Innosilicon), 0.9 (Linzhi), 1.25 to 1.67 (E9, E9 Pro) and 2.1 (Jasminer, by leaving commodity packaging). The cap was the memory's own energy per bit, and the one chip that beat it moved the memory onto the die's face.
**The timeline.** Hash live July 2015; the E3 at 32 months (announced) and 36 (shipped); the first chip over 2x at 65 months (Linzhi, December 2020); 5x at 75 months (Jasminer, October 2021); the Merge at 86 (15 September 2022). The E3's death by DAG growth: Classic first, at epoch 328 (DAG about 3.56 GB, March 2020), then Ethereum, with a 30 March 2020 firmware stretching the DDR to about block 11.4 million (about October 2020): 20 to 27 months after shipping. Ethereum's responses: Zamfir's April 2018 poll (57 percent for an anti-chip fork); EIP-1057 created 2 May 2018, a 93 percent community vote in April 2019, audits delivered September 2019, "accepted" on 21 February 2020, EIP-2538's opposition on 25 February, then stagnant; the share claim in the EIP's own text: "as much as 40 percent of the Ethereum network may now be secured by ASICs" (undated inside a 2018 to 2020 document; no year-by-year series exists). After the Merge: Classic's hashrate went 64 to 183 TH/s in one day; today Classic reads 129.9 TH/s and ETHW 2.15; at USD 0.10 per kWh every Ethash chip in the table loses money (E9 Pro minus USD 5.28 a day), and a later wave (iPollo V1 3.6 GH/s at 3,100 W, June 2022; Jasminer X16-P 5.8 GH/s at 1,900 W, August 2023) holds Classic (https://hashrateindex.com/blog/how-much-ethereum-mining-hashrate-can-other-blockchains-absorb/ ; https://2miners.com/etc-network-hashrate ; read 8 October 2026).
**The mapping to v6.** Ethash is class C in full, and its chips are the f = 1 chip of `chip-model-v3.md` section 5 at three points on the packaging ladder: commodity DRAM on a board (E3, E9: 1x to 4x), memory sized and placed per chip (Linzhi: 2x), DRAM bonded to the logic (Jasminer: 5x, the model's HBM3 row). None of v6's four layers touches a chip of this class: the program, the mixer, the op mix, the family schedule and the acceptance floor are all firmware or configuration to a controller that stores the dataset; the only layer that reaches it is layer 2, and only when the dataset passes the chip's board, which at 2 GiB plus 0.5 GiB a year is year 60 for a 32 GB board (section 4.2). Does v6 close it: **no**. The number: 5.1x per joule on GDDR7 and 7.5x on one HBM3 stack at zero premium against the 5090 unlocked, 3.6x at the 5090's 1,300 MHz knee, 2.1x at the knee with the class v4 shadow at k = 1 (`counter-asic-4-research.md` section 0); the history's measured band for exactly this chip class is 1.0x (E3) to 5.1x (Jasminer), and Jasminer's number is the model's HBM-class row reached in 2021 on a 40 nm logic die. The one thing Igneum has that Ethash did not: the honest card is latency-bound at 4-byte reads, not bandwidth-bound at 128, so the chip's energy per read is the activate's 909 pJ plus a 32-byte atom (2.0 nJ on GDDR7 against the card's measured 8.7 to 10.9 nJ marginal), which is where the 5.1x comes from, and the shadow is the only term on the card's side of that ratio.
### 2.3 RandomX (Monero, 30 November 2019): the chips, RandomX v2, and the X9's withdrawal
**The mechanism of the hash.** A VM running 8 chained programs of 256 instructions, 2,048 iterations each, over a 2 MiB scratchpad in three tiers (16 KiB, 256 KiB, 2 MiB) and a 2,080 MiB dataset derived from a 256 MiB cache by SuperscalarHash, a random superscalar program of about 450 instructions with 155 64-bit multiplies per function, tuned to a 170-cycle latency to match DRAM; double-precision floating point in all four rounding modes; the light-mode chip (cache on die) pays 760 cycles and 1,240 multiplies per item, "energy comparable to loading 64 bytes from DRAM" (https://github.com/tevador/RandomX/blob/master/doc/design.md and doc/specs.md, read 8 October 2026). Its DRAM argument: "DRAM cannot do more than about 25 million random accesses per second per bank group", about 1,500 H/s per bank group.
**The chips, and what each specialised.**
| Chip | Date | What is known of the inside | Rate, watts | Per joule against the best CPU | Source (read 8 October 2026) |
|---|---|---|---|---|---|
| Bitmain Antminer X5 | announced 27 August 2023, shipped September 2023 | "Bitmain's first RISC-V architecture CPU" (the reseller's only line); Spagni: not an ASIC but "a board containing multiple RISC-V CPU chips"; SChernykh: the chips were likely in use from about 2021, two years before sale, and do not beat Ryzen rigs per joule; core model, count, node, DRAM type and amount: NOT FOUND, no teardown | 212 kH/s at 1,350 W (157 H/W) | 1.46x over a Ryzen 9 7950X (107.5 H/W on Kryptex); a 100 W-capped Ryzen 9 9950X at 199 H/W beats it | https://criptonoticias.com/mineria/bitmain-lanza-antminer-x5-mineria-monero-asic ; https://bt-miners.com/products/bitmain-antminer-x5-monero-miner-212k-bt-miners/ ; https://pool.kryptex.com/en/device/cpu/amd/ryzen-9-7950x |
| Bitmain Antminer X9 | sales opened 26 December 2025 at USD 5,600, shipping scheduled July 2026; WITHDRAWN by mid-May 2026, refunds within hours, zero units shipped, "technical adjustments and a new strategy" through resellers, no Bitmain statement | "custom RISC-V cores specifically optimized for RandomX" (Bitmain's claim as relayed in Monero issue 10270); nothing else | 1,000 kH/s at 2,472 W (404 H/W), claimed | about 3.8x over the 7950X, claimed, never measured | https://bitmain.com.vc/news/bitmain-launches-antminer-x9 ; https://github.com/monero-project/monero/issues/10270 ; https://oneminers.com/blogs/news/whatever-happened-to-the-antminer-x9-bitmain-monero-miner (2 October 2026) |
| Pinecone INIBOX R1X | launched March 2026; shipping windows slipped from August to 10 to 18 October 2026; USD 3,200 to 4,950 | "built from ground up silicon", "optimized memory architecture for RandomX"; cores, node, DRAM: NOT FOUND; no delivered unit tested | 1,200 kH/s at 2,055 W (584 H/W), claimed | about 5.4x over the 7950X, claimed, undelivered | https://pineconebox.com/product/3 ; https://millionminer.com/news/monero-mining-guide-2026-antminer-x5-x9-pinecone-r1x-randomx |
| tevador's own "possible ASIC design" (24 December 2018, pre-release, marked outdated) | | 4 GiB of HBM for the dataset, 64 MiB of SRAM for 256 parallel 256 KiB scratchpads, 256 decoder and scheduler cores, 28 single-instruction workers; about 120,000 programs a second at about 300 W, "9 times more power efficient than a CPU" | | 9x, by the designer's own estimate of the pre-release design | https://github.com/tevador/RandomX/issues/11 |
**What the design missed, in its authors' words.** RandomX v2 (PR 317 by SChernykh, merged 17 February 2026; v2.0 released 25 March 2026; Monero mainnet activation in PR 10038, open since August 2025, no date) names the three gaps a chip or a "specially designed CPU" took: (1) CFROUND, the rounding-mode switch, "costs up to 10 percent of hashrate on Ryzen CPUs" and "this is where an ASIC or a specially designed CPU can get an easy advantage"; v2 switches rounding 16 times less often; (2) the scratchpad initialisation was the only AES, so "a dedicated circuit for scratchpad initialization" paid off; v2 puts 16 AES operations per iteration in the main loop; (3) "while CPU cores got faster over the years, RAM latency stayed basically the same", about 50 to 55 ns from tuned DDR4 in 2019 to tuned DDR5 in 2026, so the fixed 256-instruction program left latency slack a faster core could not fill; v2 lengthens the program to 384 and prefetches two iterations ahead. Work per hash rises 52.9 percent; measured CPU hash rates move from minus 12.9 percent (a 100 W-capped 9950X) to plus 8 percent (a 28 W laptop part) (https://github.com/tevador/RandomX/blob/master/doc/design_v2.md and /pull/317, read 8 October 2026). The press reading: v2 "doesn't seem to be an attempt to eliminate every form of specialization", it removes "unintended advantages that benefited hardware in version 1.0" (https://www.coinpro.ch/en/?p=42081, 31 March 2026).
**The timeline.** Live 30 November 2019; X5 at parity hardware 46 months later (September 2023), on chips SChernykh believes mined privately from about 2021 (21 months after launch); the X9 announced at 73 months and withdrawn at 78; v2 released at 76 months with a 52.9 percent work increase and no activation date; the R1X undelivered at 82 months. The X9's withdrawal is read by the trade press as Bitmain waiting for v2 rather than shipping a part the fork would hit (https://oneminers.com/blogs/news/antminer-x9-cancelled-what-bitmain-pulling-the-model-means-for-monero-mining, 31 July 2026). Corrections to the 5 October file's row 17: the X9 was not delivered in July 2026 (withdrawn, zero units), and "no fork as of October 2026" is now "v2 released, activation pending".
**The mapping to v6.** RandomX is class D (the firmware-survivable machine): every X5 claim is a many-core RISC-V board over commodity DRAM, a better CPU for a fixed VM spec, and the v2 fixes are exactly the parameters class v6 layer 1 draws (program length, the op mix's cost on the honest machine, the memory latency slack). Two readings bind: first, RandomX's whole gap is the CPU's out-of-order overhead against an in-order many-core board, and Igneum's honest machine is already the in-order many-lane design, so the X5's 1.46x has no Igneum analogue; the Igneum analogue of "a better machine for the fixed spec" is class C's memory chip at 5.1x. Second, the v2 changes show what a per-era draw of program length and op mix buys: it closes the slack a faster honest core leaves (the latency-shadow argument of class v4 in RandomX's words), and it costs the honest machine up to 12.9 percent of rate at the power-capped point, which is the Igneum premium question in another chain's numbers. Does v6 close it: yes for the class (layers 1 and 3 draw what v2 had to fork to change), and the number is the X5's 1.46x, which becomes the shadow's premium arithmetic on Igneum (2.1x at k = 1 at the knee).
**The Qubic episode (2025) as the detector's lesson.** Qubic's pool reached an average of 22.09 percent of Monero's hashrate over the campaign and 23 to 34 percent during ten withholding periods, with six-hour windows near 50 percent and never a daily 51 percent (Lee and Kim, arXiv 2512.01437, AFT 2026, read 8 October 2026); an 18-block reorg on 14 September 2025 invalidated 117 to 118 transactions. Detection rested on things the adversary controlled: one payout wallet, extra-nonce signatures in its coinbase, its own pool API; when Qubic encrypted its job messages and rotated keys those signals went, and Rucknium's warning stands that a miner split across addresses and solo-mining leaves only the orphan rate and double spends as signals. Qubic ran stock CPU miners, so the nonce-distribution method that found the 2018 and 2019 chips (MoneroCrusher: nonces clustered under about 1.34 billion of 4.3; 85.2 percent of the hashrate, about 5,400 machines at 128 kH/s) did not apply. For Igneum's detector (the 5 October addition 4) this means two instruments, not one: the per-program rate spread and nonce pattern for a chip, and a share-by-key-and-template pattern for a concentrated honest fleet; neither survives an adversary who randomises both.
### 2.2 ProgPoW (EIP-1057, May 2018): the independent review, the exploit, and the adopters
**The mechanism.** A random program re-drawn every PROGPOW_PERIOD (50 blocks in 0.9.2, 10 blocks, about 2 minutes, in 0.9.3) from the block number, so miners compile ahead; 16 lanes, a 32-register file per lane, 64 outer iterations each with 4 uint32 DAG loads per lane (256 bytes per lane-group read), 11 cache accesses into a 16 KB cache and 18 random math ops drawn from eleven (add, mul, mulhi, min, rotl, rotr, and, or, xor, clz, popcount) with KISS99 as the generator and FNV1a for merging; keccak-f800 with 32-bit words at both ends "to reduce impact on total power"; the stated aim is that "the algorithm's requirements match what is available on commodity GPUs", the stated chip gain "minimal, roughly 1.1 to 1.2x", with the remaining chip levers named as removing the graphics pipeline, the floating-point units and minor merge-function tweaks (https://eips.ethereum.org/EIPS/eip-1057 and https://github.com/ifdefelse/ProgPOW, read 8 October 2026).
**The independent review, exactly.** Least Authority (report version 9 September 2019): no issues, five suggestions. Suggestion 2, the light-evaluation attack, in the report's words: "on-die scratchpad memory of around 100 MB is possible in ASICs, that we can fetch at least 128 bytes during a single read, and that such a read might have a latency in the range of one to some tens of cycles"; a chip replaces every DAG read with calc_dataset_item(cache, i) over an on-die cache, at a latency near DATASET_PARENTS x k1, "as low as about 300 cycles"; "the energy expended per bit to access DRAM is about 3 pJ per bit, but when the memory access is on-chip, it decreases to 0.3 pJ per bit, which is a 10x improvement"; conclusion: "efficient light-evaluation attacks may become possible within a few years. This is also an issue that applies to Ethash"; the mitigation offered: raise DATASET_PARENTS from 256 to 512 (which 0.9.4 did), and "for details on the related hardware advancements, please see Bob Rao's corresponding audit report". Suggestion 5: "hardware targeting machine learning is also useful for ProgPoW mining" (the PDF at https://leastauthority.com/static/publications/LeastAuthority-ProgPow-Algorithm-Final-Audit-Report.pdf, text extracted, read 8 October 2026). Bob Rao (6 September 2019): "the only meaningful metric is Energy per Hash"; Ethash chips "about 1.6x hashrate per watt over GPUs"; "10/7 nm processes provide up to 25 Mbits per mm^2 of SRAM and 100 M transistors per mm^2"; "with sufficient on-chip memory available, ProgPOW ASICs with << 0.1x E/H over GPUs can be built"; three chip approaches costed (the whole DAG on die, "possible in 2025+"; a custom stacked memory; the cache only, "about 51 MB as of 30 August 2019", with the item recomputed, "512 MB SRAM" on the slide); the DAG-on-die economics on a three-year Moore cadence: a single die holding a 6.49 GB DAG in 2024 to 2025 at 532 mm^2 and USD 221 per good die (USD 34 per GB), or sixteen dies of 33 mm^2 at USD 6.51 each; "a die that can hold the logic and entire DAG at any point in time becomes cost effective at around 2025 and beyond"; the 16-die split "becomes cost effective today": 16 x USD 6.62 of silicon plus USD 16 of package plus USD 25 of PCB plus USD 25 of heatsink and interface, "about USD 172 total", against "about USD 240" for a GPU board with "8 GB GDDR6 about USD 150"; a 10 nm-class chip "USD 20 M+" and "1+ year to develop, can be done if there is a 150-day ROI to miners" (the PDF at https://github.com/ethcatherders/progpow-audit, text extracted, read 8 October 2026).
**The exploit.** Kik, 4 March 2020: the 64-bit seed carried between the two keccak passes is too small; fix a seed and compute its mix once, grind an extra-nonce in the header to meet the difficulty on the final keccak, then scan nonces until keccak_progpow_64(header_hash, nonce) equals the seed; the memory path runs once per 2^64 nonces and the rest is keccak, "ASICs benefit most when network difficulty exceeds 2^50"; 0.9.4 widened the carried state from 64 to 256 bits (the digest of the first keccak plus the mix plus padding) (https://github.com/kik/progpow-exploit ; https://github.com/ifdefelse/ProgPOW ; read 8 October 2026).
**Linzhi's claim.** 8 January 2019: "shocked" by ProgPoW with USD 4 M invested, and a stated intention "to study the feasibility, and then build, ProgPoW ASICs"; the repository recording their claim puts a ProgPoW chip at 3x to 8x (https://github.com/Souptacular/linzhi ; https://forklog.com/proizvoditel-majnerov-linzhi-vystupil-protiv-realizatsii-predlozheniya-progpow/ ; read 8 October 2026). No ProgPoW chip was ever shown.
**The timeline and the adopters.** EIP created 2 May 2018; a 93 percent vote of 2.93 M ETH in April 2019; both audits September 2019; "accepted" on the 21 February 2020 call; EIP-2538's opposition 25 February; the 6 March 2020 call with "frustration but little progress"; stagnant since; the Merge 15 September 2022. KawPow (Ravencoin, 6 May 2020), FiroPoW (26 October 2021), ProgPowZ (Zano), Sero and Quai (January 2025) run ProgPoW variants; no chip is listed for any of them on WhatToMine or asicminervalue as of 8 October 2026 (https://whattomine.com/coins/234-rvn-kawpow/gpus ; https://www.asicminervalue.com/), on prizes that never reached the market caps at which the 2018 chips appeared (the 5 October file, section 2.5).
**The mapping to v6.** ProgPoW is class D (a sequencer over eleven ops reads the per-period program as configuration) and class E (Kik). Its review is the one piece of the record that priced Igneum's own chips before Igneum did: the light-evaluation attack is the f = 0 recompute chip (M16, 0.92x at the op budget with the mixer at x8), and Rao's 16-die DAG holder at USD 172 is the f = 1 chip at USD 470 of memory and board. Does v6 close it: the class D half yes (layers 1 and 3 are ProgPoW's period change made an era draw, with no fork), the class E half yes (Igneum's seed is 256 bits through the VDF; layer 4 is the acceptance-side test the audits said to add), and the Rao half no (class C, section 2.1). The number: ProgPoW claimed 1.1x to 1.2x against a conventional compute chip and never priced the memory-system chip; Igneum's model gives that chip 5.1x.
### 2.4 Cuckoo Cycle (Grin, January 2019): the GRN1, the G32, the iPollo G1 and the 2025 bounty
**The mechanism of the hash.** Find a 42-cycle in a random bipartite graph of 2^31 or 2^32 edges from siphash; the lean solver keeps "1 bit per edge and 1 bit per node in one partition", bottlenecked by random node-bit access, which "requires tons of SRAM, which is lacking on CPUs and GPUs, but easily implemented in ASICs"; the mean solver keeps 33 bits per edge and is bandwidth-bound, about 4x faster; Tromp: "our primary PoW of Cuckatoo31+ is intended to be mined by ASICs"; the family is "a Proof of SRAM" (https://github.com/tromp/cuckoo ; https://forum.grin.mw/t/cuckatoo31-im-mutability/2442 ; read 8 October 2026). The memory geometry a chip needs (the 13 November 2018 feasibility thread): the 512 MB edge bitmap is accessed sequentially and can sit in external DRAM (96 GB/s with 128 MB on chip); the node bitmap must be SRAM; Cuckatoo31 fits one die at "256 + 64 = 320 MB of on-chip memory", Cuckatoo32 needs "at least 640 MB" or 512 MB of SRAM plus 512 MB of serial DRAM; "trimming is over 99 percent of the effort" (https://forum.grin.mw/t/cuckatoo32-feasibility/1199 ; https://forum.grin.mw/t/advice-on-cuckatoo-hardware-implementation/12042). The original "several orders of magnitude" time-memory claim fell to Andersen's edge trimming on 31 March 2014, two months after publication, and the design took it as its baseline.
**The chips.**
| Chip | Dates | Mechanism | Rate, watts, price | Against a GPU | Source (read 8 October 2026) |
|---|---|---|---|---|---|
| Obelisk GRN1 (Cuckatoo31) | announced 17 January 2019; chip details 20 March; sale 9 April (Mini 70 GPS at 400 W for USD 2,000; GRN1 420 GPS at 2,200 W for USD 10,000; Immersion 840 at 4,400 W for USD 20,000; shipping October 2019); CANCELLED 19 July 2019 with full refunds | one die, TSMC 16 nm, "a full 512 MiB of memory on board" (SRAM), 150 GPS at 800 W per chip, "thousands of hashing cores and memory banks", siphash plus blake2b, two sorter types; cancelled for the Cuckatoo31 phase-out, Grin under USD 2 in May 2019 and funding | 420 GPS at 2,200 W planned | about 50x per joule against a GTX 1080 Ti at about 0.9 GPS and 250 W on C31 (approximate), planned, never built | https://forum.grin.mw/t/obelisk-grn1-chip-details/4571 ; https://forum.grin.mw/t/obelisk-grn1-full-sale/4773 ; https://forum.grin.mw/t/grn1-cancellation-announcement/5624 |
| Innosilicon G32 (C31+ and C32+) | announced 17 April 2019 (G32-Mini 21.5 GPS at 140 W for USD 788; G32-1800 328 GPS at 1,800 W for USD 9,388; delivery from August 2019); CANCELLED 16 January 2020 citing foundry delays | about 100 chips at about 1.8 to 1.9 GPS each on C32 (an investor's figure) | never shipped | | https://forum.grin.mw/t/innosilicon-grin-miner-g32-preliminary-specification/4842 ; https://forum.grin.mw/t/innosilicons-grin-asics-canceled/6932 |
| iPollo G1 (Cuckatoo32) | December 2020 | 30 chips at 12 nm; whether the node bits sit in SRAM or the edge bitmap in DRAM is not published; Tromp doubts it is multi-chip in Innosilicon's sense | 36 GPS at 2,800 W, USD 9,000 | about 3x per joule against an RTX 4060 at 0.45 GPS and 110 W | https://pool.kryptex.com/device/asic/ipollo/g1 ; https://miningboard.com/algorithms/Cuckatoo32 |
**The 2025 bounty.** Stephan Theisgen claimed the USD 10,000 linear time-memory trade-off bounty on 11 April 2025 (a solver at N/k bits at most 10k times slower, any k at or above 2), paid 30 April; the measured penalty about half an order of magnitude past linear; Tromp's reading: a chip with N/k bits must hash each edge "roughly (k + 1000) times" against under 6 for the lean miner, so memory can be traded for time but not for energy, and Cuckatoo "remains a Proof of SRAM" (https://forum.grin.mw/t/another-cuckatoo-bounty-succesfully-claimed/11739, read 8 October 2026).
**The mapping to v6.** Class B. Cuckoo's resource was SRAM size at 320 to 640 MB per die, and a 16 nm die with 512 MiB of SRAM was designed, priced and sold before the economics killed it; the one chip that shipped sat at 3x because half its working set stayed in DRAM. Layer 2 answers it the way the chip model already does: Igneum's 256 MiB cache is the GRN1's die (128 mm^2 at N5, `sram-mirror.md`), and the 2 GiB dataset above it is what the lean solver never had to hold; the time-memory curve Cuckoo got wrong by 50x and then bounded in 2025 (linear in time, not in energy) is the curve `chip-model-v3.md` section 5 draws for Igneum (monotone; the f = 0 end pays 6.3 nJ and 9,360 ops per item against 1.2 to 2.0 nJ for a stored one), and its verdict is the same as Tromp's: memory can be traded for time, not for energy. Does v6 close it: yes, and it was closed at class v3. The number: 50x planned on C31 and 3x shipped on C32; Igneum's f = 0 chip 1.86x per joule and the f = 1 chip, which Cuckoo did not have because its memory was never a DRAM-scale random-read set, 5.1x.
### 2.5 Equihash 200,9 (Zcash, October 2016): the Z9 and the parameter-following chip
**The mechanism of the hash and its claim.** Wagner's generalised birthday problem with algorithm binding; the paper's claim: a PoW needing "700 MB of RAM" that "increases the computations by the factor of 1000 if memory is halved" (https://eprint.iacr.org/2015/946, read 8 October 2026). Zcash chose (200, 9), which solvers run in about 144 MB (approximate); no trade-off-resistance bound was ever proved for Equihash (Alcock and Ren, 2017, cited through the Fudan paper below).
**The chips and the mechanism.** Bitmain's BM1740 (Z9 mini, announced 3 May 2018 at 10 kSol/s and 300 W, shipped June; Z9 September 2018, 42 kSol/s at 970 W on 48 chips) is "a single-chip Equihash miner", "presumably with around 128 MB of memory", eDRAM or SRAM "an open question" (Tromp, 7 June 2018, https://forum.z.cash/t/let-s-talk-about-asic-mining/27353/3332): the whole (200, 9) working set on one die, which the 1,000x claim had assumed impossible at that size. A (144, 5) solver needs over 1.6 GB and cannot fit; Tromp "physically inspected the product and did not find enough memory to handle (144, 5)". Vorick's architecture (13 May 2018) is the other route: "a basic architecture for equihash ASICs that would be able to successfully follow a hardfork that chose any set of parameters", with "massive speedups and efficiency gains over GPUs", because on a chip "you can merge the memory and computation together ... do most of your manipulating in-place" (the essay, through https://steemit.com/crypto/@waraa/the-state-of-cryptocurrency-mining). The published design of that route: Bai, Gao, Hu and Zhang, NDSS 2019, an adversary solver whose sort step is a linear-time insertion sorter of 2,048 "smartcell" flip-flop chains feeding merge stages buffered in off-chip DDR4 (list 1,600 Mib, pairs 2,016 Mib for (200, 9)), pair generation and XOR on small MCUs; simulated at SMIC 28 nm: 40.6 Sol/s at 500 MHz for 0.75 to 0.78 W, 52 to 54 Sol/J against about 4 for the best GPU software, "at least 10x" and parameter-independent (https://www.ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_09-5_Bai_paper.pdf, read 8 October 2026). Later chips: Innosilicon A9 (June 2018, 50 kSol/s at 620 W, USD 9,999); Z11 (April 2019, 135 kSol/s at 1,418 W, 12 nm); Z15 (420 kSol/s at 1,510 W); Z15 Pro (June 2023, 840 kSol/s at 2,780 W). Against a GTX 1080 Ti at 735 to 785 Sol/s and 250 to 305 W (about 2.7 Sol/J): Z9 mini 12x, Z9 16x, A9 30x, Z11 35x, Z15 Pro 110x (https://www.asicminervalue.com/miners/bitmain/antminer-z9 ; https://www.asicminervalue.com/miners/bitmain/antminer-z15-pro ; https://en.wikibooks.org/wiki/ZCash_mining_GPU_Comparison/GPU_Mining ; read 8 October 2026).
**The timeline.** Hash live 28 October 2016; three groups mining on secret chips before the Z9 announcement (Vorick); the Z9 mini at 18 months; the Zcash Foundation's statement of 8 May 2018 asked whether chips "could handle different parameters of Equihash" and the community vote of June 2018 went 45 to 19 against prioritising resistance; no fork; proof of stake announced November 2021; the Z15 Pro at 80 months.
**The mapping to v6.** Class B, with a lesson for layer 1: Equihash's parameters (n, k) were the knob the forks turned (Bitcoin Gold to 144,5; Beam to 150,5; Flux to 125,4), and a chip was designed to follow "any set of parameters" by keeping the memory off die and the sort on it. A per-era draw of a parameter a chip can follow is a configuration to it; a draw of the memory SIZE is the one that forced the Z9's single die to fail on (144, 5), which is layer 2's mechanism, not layer 1's. Does v6 close it: yes by layer 2 (a 2 GiB set is not a die), and the parameter-following chip is the honest warning for layer 1's draws. The number: 12x at the first chip, 110x by 2023, against a hash whose 1,000x penalty claim never had a proof; Igneum's claim for its curve rests on a drawn curve (`chip-model-v3.md` 5.4) and the in-house pass's exact pebbling optimum (adv-cache-3), and still has no proof.
### 2.6 Scrypt and Argon2: the Litecoin chips, the lookup gap, and MTP
**Scrypt (Tenebrix and Litecoin, 2011; N = 1,024, r = 1, p = 1: a 128 KB scratchpad).** The mechanism of every scrypt chip is one 128 KB of on-die SRAM per hashing core and many cores per die: Watkins (2014) "there only needs to be 128 KB of memory per processor ... one core driving a 128 KB cache", SRAM chosen over every other memory as fastest, salsa20/8 about 60 percent of the runtime and memory access 38 percent (https://arxiv.org/pdf/2208.02160); the BM1485 of the L3+ (June 2017, 504 MH/s at 800 W): 12 cores per chip, "every BM1485 integrates on-die SRAM to hold that scratchpad", 28 nm, 288 chips per unit, about 1.7 MH/s per chip (so about 1.5 MB of SRAM per chip, arithmetic) (https://d-central.tech/mining-glossary/bm1485/ ; https://www.asicminervalue.com/miners/bitmain/antminer-l3-504mh); the L7 (November 2021, 9.5 GH/s at 3,425 W, USD 15,000, 0.36 W per MH against the L3+'s 1.58): the BM1489 at TSMC 7 nm, 480 chips (https://d-central.tech/mining-glossary/bm1489/ ; https://cryptoage.com/en/2550-bitmain-antminer-l7-is-a-new-asic-miner-for-litecoin-and-dogecoin.html); the Innosilicon A2 (21 April 2014, 28 nm, 1.6 to 1.8 MH/s per chip at 10 W, about 150 MH/s per box at 1 kW: https://www.design-reuse.com/news/34403/innosilicon-28nm-litecoin-asic-reference-miner.html); the KnC Titan (March 2014, 250 MH/s at 800 to 1,000 W, USD 9,995, "4 chips x 2,284 cores": https://www.coindesk.com/markets/2014/03/28/kncminer-updates-titan-spec-promises-250mhs/), whose 2,284 cores cannot each hold 128 KB on a 2014 die, so it shared scratchpads or took the time-memory trade-off (not confirmed). The trade-off itself is in the designer's record: Percival (18 November 2012) on storing every other scratchpad entry: memory halved for about 25 percent more BlockMix work, area-time about 0.625x, the trade favouring the attacker at 2x to 4x reductions, "already in the paper's cost estimates" (https://mail.tarsnap.com/scrypt/msg00092.html; all read 8 October 2026). Against an R9 280X at 700 to 740 kH/s and 340 to 450 W at the wall: A2 about 70x, L3+ about 300x, L7 about 1,300x per joule (derived, approximate). Scrypt-N (Vertcoin 2014: N doubling by timestamp up to 2^30) was dropped on 13 December 2014 for Lyra2RE "as a proactive defense against emerging Scrypt-N capable ASICs", because raising N "simply involves doing more iterations" and more SRAM or a larger lookup gap (https://vertcoinproject.org/vertcoin_whitepaper.pdf ; https://coincentral.com/what-is-vertcoin-a-beginners-guide/).
**Argon2 as a proof of work (MTP, Zcoin, 10 December 2018).** Argon2d over 4 GB with a Merkle tree; Dinur and Nadler (2017): malicious proofs with under 1 MB, 1/3,000 of the honest memory, at a computation penalty of 170, "more than 55,000 times faster than what is claimed by the designers", with a 2^64 one-time precomputation, by injecting chosen blocks that steer Argon2d's data-dependent addresses (https://eprint.iacr.org/2017/497); MTP 1.2 patched it before launch; no Argon2 chip was ever built; Firo replaced MTP with FiroPoW on 26 October 2021 (https://firo.org/2021/10/01/firopow-and-instantsend-release.html). Yescrypt and yespower (GlobalBoost-Y 2014; Yenten, Cranepay, Tidecoin on yespower from 2018; L2-latency-bound sequential work: https://www.openwall.com/yespower/): no chip found, small prizes.
**The mapping to v6.** Class B throughout, and the parameter-growth lesson for layer 2 in its oldest form: Scrypt-N's automatic growth was abandoned because a chip follows a scratchpad that grows by doubling the SRAM it already has, and Percival's own 2012 note says the time-memory trade favours the chip at 2x to 4x. Does v6 close it: yes by layer 2 (no die holds 2 GiB; the curve is monotone against partial stores); the lookup-gap lesson is the reason the dataset's chained cache has a drawn pebbling optimum (adv-cache-3) rather than a claim. The number: 1,300x for scrypt by 2021; Igneum's f = 0 chip at 1.86x per joule. MTP is class E (section 4.4).
### 2.7 to 2.9 KawPow, Autolykos, Octopus: the no-chip hashes, and why
| Hash | Live | Mechanism | Chip status, 8 October 2026 | Why no chip (the honest reading) | Source |
|---|---|---|---|---|---|
| KawPow (Ravencoin; Neoxa, Clore, Meowcoin, Neurai) | 6 May 2020 | ProgPoW 0.9.4 with a per-block program; "no additional future algorithm forks are envisaged" | none listed on WhatToMine or asicminervalue | class D on a small prize: Ravencoin's cap never reached the 2018 cluster's | https://whattomine.com/coins/234-rvn-kawpow/gpus ; https://github.com/RavenProject/Ravencoin/blob/master/roadmap/README.md |
| Autolykos v2 (Ergo) | February 2021 (v1 July 2019) | a k-sum (k = 32) over a Blake2b table of 2^26 elements of 31 bytes (2.08 GB) growing about 5 percent per 51,200 blocks from block 614,400 to a cap of 2,143,944,600 elements at block 4,198,400; v1's non-outsourceable puzzle removed because "large players could bypass this resistance using smart contracts" | none | class C territory (a table read per hash) on a small prize; its growth rule is the one automatic schedule in the record untested by a chip; f2pool and Ergo's own docs call it resistant with no chip named | https://docs.ergoplatform.com/mining/autolykos/ |
| Octopus (Conflux) | October 2020 | Ethash-style DAG (the "dense matrix step" unverified in the source) | none | as above; f2pool: "cannot be efficiently mined with FPGAs or ASICs" | https://f2pool.io/mining/guides/how-to-mine-conflux/ |
| Verthash (Vertcoin), FishHash (Iron Fish from April 2024, Karlsen) | January 2021; April 2024 | a 1.2 GB table from the chain's headers; a 4,608 MB constant dataset with Blake3 and 512 iterations | none | the same class as Ethash's chips, on prizes under the 2018 cluster | https://fips.ironfish.network/fips/fip-3-memory-hard-mining-algorithm |
The reading for v6: "no chip" on a DRAM-scale random-read hash is an economic fact, not a design one (the 5 October file, section 2.5: compute-bound hashes got chips at USD 20 K to 30 K of daily issuance, Ethash at USD 7.6 M). Every hash in this table is class C and none of them has been tested at a prize that pays for a controller project; the Ethash record is the test, and it read 1x to 5x.
### 2.10 kHeavyHash (Kaspa, November 2021): the KS chips
**The mechanism.** cSHAKE256 of the header and nonce, a 64 x 64 matrix of 4-bit values generated from the pre-PoW hash, a nibble-wise matrix-vector multiply, XOR, a final cSHAKE (https://github.com/kaspanet/rusty-kaspa/blob/master/consensus/pow/src/lib.rs, read 8 October 2026); designed for optical and specialised hardware; the chip wires the multiply as a fixed pipeline. IceRiver KS0 (September 2023, 100 GH/s at 65 W), KS1 (1 TH/s at 600 W), Antminer KS3 (August 2023, 9.4 TH/s at 3,550 W), KS5 Pro (March 2024, 21 TH/s at 3,150 W), KS5L (April 2024, 12 TH/s at 3,400 W); against an RTX 4090 at 2.08 GH/s and 226 W: KS0 about 170x, KS5 Pro about 720x per joule (https://www.asicminervalue.com/miners/bitmain/antminer-ks5-pro-21th ; https://www.kryptex.com/overclocking/nvidia-rtx-4090-micron-24gb-medium-overclock ; read 8 October 2026). Timeline: 17 to 20 months to the first chip; the GPU share negligible by late 2023; seven forks left Kaspa to re-resist (the 5 October file, row 23). Node: not found.
**The mapping to v6.** Class A. The matrix multiply is a warning for the reserve's mm8 family, not for the hash: a fixed 64 x 64 nibble multiply is the cheapest thing silicon does, and the measured rows agree (the 5090's int8 MAC at 1.4 to 4.1 pJ against a 5 nm array's claimed 0.04 to 0.4, `counter-asic-4-research.md` 15.1a). Does v6 close it: yes, closed since class v2 (no fixed function to unroll); the number, 720x, is what a fixed pipeline does to compute-bound work, and the reserve's ordering (section 4.3) keeps mm8 last for exactly this reason.
### 2.11 CryptoNight (Bytecoin 2012, Monero 2014): the X3, the secret chips, and four forks
**The mechanism of the hash.** 524,288 iterations of an AES round plus an 8-byte multiply over a 2 MB scratchpad sized to a 2014 per-core L3; latency-bound at SRAM scale.
**The chips.** Bitmain Antminer X3, announced 15 March 2018 at 220 kH/s and 550 W (465 to 470 W measured), 180 BM1700 chips on three boards, USD 11,999 for batch 1 falling to USD 1,900; no teardown or vendor description of the BM1700 exists (node, SRAM, AES units not found). The arithmetic is the mechanism: 1.2 kH/s and about 2.6 W per chip is one or two 2 MB scratchpads in on-die SRAM with a hardware AES round per chip, and nothing else reaches that rate in that power (approximate, inference). Baikal Giant N, March 2018, 20 kH/s at 60 W. Against a Vega 64 at 2,009 H/s and about 200 W card power (about 10 H/W) the X3 is about 40x per joule; against a Threadripper 1950X at about 1,000 H/s and 185 W, about 75x (approximate) (https://www.asicminervalue.com/miners/bitmain/antminer-x3-220kh ; https://www.asicminervalue.com/miners/baikal/bk-n ; https://hothardware.com/reviews/monero-mining-with-amd-ryzen-threadripper ; read 8 October 2026).
**The secret chips.** Monero's own 2018 review: by early 2018 "it was estimated that 80 to 90 percent of the network was specialized hardware" (https://web.getmonero.org/2019/02/12/2018-year-in-review.html); about half the hashrate (about 500 MH/s of 1,000) left at the v7 fork on 6 April 2018; Krawiec-Thayer's nonce study (24 November 2018) found half of all blocks with nonces in the lowest 0.002 percent of the space, patterns that "evaporated abruptly" at the fork (https://www.hackernoon.com/utter-noncesense-a-statistical-study-of-nonce-value-distribution-on-the-monero-blockchain-f13f673a0a0d). Vorick (13 May 2018, through secondary coverage): secret Monero ASIC mining "since early 2017, making up 50 percent of the hashrate". The timeline from the hash to the first secret chip is therefore about 33 months (April 2014 to early 2017), not the 43 the 5 October file gives (which counted to the fork); the announced chip came at 47.
**The four forks and what each cost a chip.** v7 (6 April 2018): a one-byte tweak to the main loop; half the hashrate left; "a precaution and deterrent". v8 (18 October 2018, height 1,685,555): a whole-cache-line shuffle (4x the bandwidth demand) plus a 64:32 division and a 64-bit square root per iteration, 5 to 10 percent off CPU rate; the hashrate went from about 320 MH/s to just under 1,000 MH/s before March 2019 with chip nonce patterns visible from December: chips back inside two months, dominant inside four (https://decrypt.co/14421/ ; https://en.cryptonomist.ch/2019/05/08/mining-monero-hashrate-pow-change/). CryptoNight-R (9 March 2019, brought forward from April after the detection): a per-block random sequence of 60 to 69 integer instructions (63 on average; MUL 40 percent, XOR 23, SUB 12, ADD 12, ROR 8, ROL 6) over 9 registers, seeded by height so miners compile ahead; SChernykh's claim is a chip's minimum latency for the random math "at least 2.5 times higher" than the DIV plus SQRT it replaced (a chain of 15 multiplies against 6), with up to 1.5x more for an out-of-order chip; a hardware engineer in the PR thread estimated a chip could still do about 18 ns per iteration, comparable to a CPU (https://github.com/SChernykh/CryptonightR ; https://github.com/monero-project/monero/pull/5126). The hashrate fell from about 1 GH/s to 140 MH/s and settled at 300 to 350 MH/s; no CN-R chip is documented in its nine months. RandomX followed on 30 November 2019.
**The mapping to v6.** CryptoNight is class B (SRAM-scale memory: layer 2 closes it, the 2 GiB dataset is 1,000 mm^2 of SRAM even at N5) and class D (the forks: v7 and v8 kept the machine's shape and the chips returned; CN-R changed what the machine had to be, a per-block random program, and no chip came in nine months, which is the per-epoch random program Igneum ships). The number: 40x per joule for the X3 against a GPU; the Igneum analogue, the f = 0 recompute chip that holds the 256 MiB cache on die, reads 0.92x at the op budget and 1.86x per joule (`chip-model-v3.md` 5.4), and CN-R's 2.5x latency claim is the fixed-shape mixer's 3x factor in the other direction. The honest residue: Monero's chips were found by nonce pattern four months after a fork at 85 percent of the hashrate; Igneum has no detector yet.
### 2.12 X16R (Ravencoin, January 2018): a drawn order over fixed functions
**The mechanism and the chips.** Sixteen hash functions in an order set by the previous block hash, a per-block automatic change with no fork. The sequencing changed; the sixteen primitives did not, so one large FPGA holding all sixteen cores needs only per-block routing: BittWare and SQRL's CVP-13 (Xilinx VU13P) was announced on 7 September 2018 naming "X17r, X16r and TimeTravel10" (https://www.cryptoninjas.net/2018/09/07/squirrels-research-labs-and-bittware-launching-new-fpga-crypto-mining-hardware/ ; https://www.bittware.com/cvp-13 ; read 8 October 2026). An unknown pool held 10 to 20 percent of blocks in February 2019, 30 to 40 in March, 45 by 11 July; the OW Miner OW1 (September 2019, 182 MH/s at 1,500 W, about USD 500) and SKC Turing R1 (680 MH/s at 800 W, about USD 1,500) were sold as ASICs, their insides unconfirmed; against a P102-100 at 35 MH/s and 219 W the OW1 is 0.75x and the R1 about 5x per joule (https://cryptoage.com/en/1782-asics-ow-miner-ow1-and-skc-miner-turing-r1-for-the-x16r-algorithm-exist.html ; https://miningboard.com/algorithms/X16R). X16Rv2 (1 October 2019) swapped one hash in; on 30 January 2020 Tron Black called the chips' return "evident"; KawPow followed in May 2020; Ravencoin's roadmap records "ASICs have been developed for X16R (and X16Rv2)" (https://cointelegraph.com/news/ravencoin-community-clash-over-mining-algorithm-continues ; https://github.com/RavenProject/Ravencoin/blob/master/roadmap/README.md).
**The mapping to v6.** Class D in its purest form, and the warning for layer 1: a draw over a FIXED set is a configuration to a chip that holds the set. Igneum's op-mix draw is over twelve families a chip holds from genesis; what the draw does cost a chip is nothing, and what it costs the honest card is the per-vendor energy table. Does v6 close it: the fixed-function lane is closed by the per-epoch program (there is no sixteen-core pipeline to route), and the draw itself is a governance device. The number: 5x for the one X16R box with a plausible chip inside; the GPU-without-graphics sequencer's gain on Igneum's program side is bounded by that kind of figure, and its memory side by class C's 5.1x.
### 2.13 Lyra2REv2 (Vertcoin, August 2015): FPGA first, then the Zig Z1
A memory-hard sponge (Lyra2 at T = 1, R = 8, C = 256, p = 1: a matrix small enough for on-die SRAM per core, on the order of 200 KB, approximate) inside a chain of hashes. The FPGA came first: an academic Lyra2 core on 16 July 2018 and a full FPGA miner at 2.6 to 3.7 MH/s and 323 to 432 nJ per hash, "significantly more energy efficient than both a GPU and a commercially available FPGA-based miner", which confirms commercial bitstreams before the chip (https://arxiv.org/abs/1905.08792); the Dayun Zig Z1 on 19 September 2018: 6.8 GH/s at 1,200 W, 28 nm, USD 8,000, "equivalent to 100 GeForce GTX 1080 Ti", about 20x per joule against a 1080 Ti at about 68 MH/s and 250 W (https://cryptoage.com/en/1231-first-asic-miner-lyra2rev2-dayun-zig-z1.html; read 8 October 2026). Vertcoin 0.14.0 forked at block 1,080,000 (1 February 2019) "to rid the network of the current generation of Lyra2REv2 ASICs and FPGAs" with Lyra2REv3 (R = 32, p = 4: 16x the memory), then Verthash in January 2021 (https://github.com/vertcoin-project/vertcoin-core/releases/tag/0.14.0). The 22 reorgs of October to December 2018 and the December 2019 attack came through rented hash on a hashrate the forks had reset (the 5 October file, row 7). Mapping: class B (layer 2 closes it) and lesson 5 (the fork reset the hashrate to a rentable size, which v6's layers 1 and 3 never do). The number: 20x; Igneum's f = 0 chip 1.86x.
### 2.14 Eaglesong (Nervos, November 2019) and Blake3 (Alephium, November 2021): compute, embraced
Eaglesong: a new sponge; the Toddminer C1 in February 2020 at 4 months, the Antminer K5 (April 2020, 1.13 TH/s at 1,580 W), the K7 at 63.5 TH/s and 3,080 W; about 100x per joule against an RTX 2080 Ti at about 1.5 GH/s and 220 W (approximate) (https://www.asicminervalue.com/miners/bitmain/antminer-k5-1130gh ; https://miningboard.com/algorithms/Eaglesong). Blake3: double Blake3, chosen as chip-friendly; the Goldshell AL-BOX (May 2024, 360 GH/s at 180 W), Antminer AL1 (15.6 TH/s at 3,510 W) and AL1 Pro (August 2024, 16.6 TH/s at 3,730 W), AL3 (8 TH/s at 3,200 W); about 100x to 220x per joule against an RTX 4090 at 6.0 GH/s and about 300 W (https://www.asicminervalue.com/miners/goldshell/al-box ; https://whattomine.com/asics/294-bitmain-antminer-al1-pro). Blake2s on Kadena: the Goldshell KD5 (March 2021, 18 TH/s at 2,250 W) and Antminer KA3 (166 TH/s at 3,154 W) against a GTX 1660 Super at 633 MH/s and 79 W: about 1,000x and 6,500x (https://www.asicminervalue.com/miners/goldshell/kd5 ; https://miningboard.com/algorithms/Blake%20%282s-Kadena%29). NexaPow (SHA-256 plus a secp256k1 Schnorr signature per nonce, "useful ASICs"): the DragonBall A21 (December 2024, 3.4 GH/s at 1,800 W, USD 6,999) is only about 2.2x per joule against an RTX 4090 at 320 MH/s and 380 W, because big-integer elliptic-curve arithmetic leaves a fixed pipeline little to strip (https://spec.nexa.org/mining/NexaPOW/ ; https://www.asicminervalue.com/miners/dragonball-miner/a21 ; all read 8 October 2026). Mapping: class A, closed since class v2; the numbers (100x to 6,500x) are what a fixed function costs, and NexaPow's 2.2x is the one compute-bound row where the chip's edge stayed small, because the work was already a wide multiplier chain, which is the shape of the ALU shadow's k band (0.3 to 0.8) in another chain's numbers.
## 3. The three lessons, with the evidence
**Lesson 1. The chip that stores the dataset is firmware-immune to every draw; only joules and memory growth move it.** Evidence: the five Ethash chips (section 2.1) never touched Ethash's compute and never needed to; Rao's audit said in 2019 that "the energy expended to move data from DRAM to compute are the same for GPU or ASIC" and that the only lever a chip has is the memory's own energy per bit, which Jasminer took by bonding the DRAM to the die; the Least Authority audit's conclusion that "the random math core likely prohibits the build of a light-evaluation based ASIC" was about the f = 0 chip and said nothing about the f = 1 chip, which is the one that shipped on Ethash in three forms. On Igneum's side the identity of `counter-asic-4-research.md` section 2 says it in one line: at zero premium the edge is E_card over E_mem and no hash change touches it. What v6 inherits: 5.1x per joule on GDDR7 at zero premium against the 5090 unlocked, 3.6x at its 1,300 MHz knee, 2.1x with the class v4 shadow at k = 1, and USD 2.8 against 14.7 per MH/s. What binds on v6: every per-era draw of layer 1 and every family epoch of layer 3 must be priced against this chip as a configuration change (a recompile per epoch, a new mapping per era) and never claimed as a cost to it; the public text's "under 2x" stays worded against the recompute chip, as the 6 October verdict already requires.
**Lesson 2. Automatic change beats the human fork only where it costs the chip a redesign, and the one parameter that does is the memory.** Evidence: Grin's three Cuckaroo tweaks (17 July 2019, 15 January 2020, 16 July 2020) each changed the edge function and no chip ever shipped for the lane, but each was a hard fork with a new solver and the lane was scheduled to die; Monero's v7 and v8 kept the machine's shape and the chips were back inside four months, CN-R changed the machine and no chip came in nine months, RandomX changed it again and the X5 took 46 months; X16R's per-block order cost the FPGA nothing; Scrypt-N's public, slow growth was abandoned before a chip because the chip could be sized for years of it; Ethash's DAG growth is the one automatic rule in the record that killed a shipped chip, and it killed the one chip whose memory was sized to the card fleet's own limit (4 GB), 20 to 27 months after shipping. The compile and design cycles bound the race: Bitmain built the A3 in about 5 months and Halong the B52 in 9 (Vorick), a full Vivado compile on a mid-size part runs 42 to 160 minutes and hours on a large one (PRflow, FPT 2019), so an hourly program outruns every compile and a six-monthly change outruns no chip. What binds on v6: layers 1 and 3 close the governance failure (no fork, no hashrate reset to a rentable size, which cost Vertcoin two 51 percent attacks) and tax a sequencer chip die area, not architecture: Rao's own figure is about 1 M gates and 0.025 mm^2 at 10 nm for ProgPoW's whole inner loop, so a lane array carrying every reserve family is the class v4 shadow core's 30 mm^2 of N5 and USD 25 to 40, not a wall. Layer 2 is the one real lever, and its value is its floor and ceiling, not its tracking: the floor keeps class B closed (2 GiB is 1,000 mm^2 of SRAM at N5), and a ceiling under the honest tiers' memory is a requirement, because any rate that ages out a 32 GB chip board retires the 8 GB card first.
**Lesson 3. A steered or biased address pattern is always found after launch unless the test lives in the acceptance rule, and every new draw needs its own null.** Evidence: Kik's exploit came five months after two audits that named the seed's keccak as a thing to scrutinise and three days after the EIP was declared dead; Dinur and Nadler found MTP's under-1 MB proof before launch only because the construction was published and reviewed, and the fix was a construction change; AP-F8-1 was found by the attack-pass lane one day after class v4 reached the devnet, in 96.6 percent of the class's programs, and took three sub-versions and class v5's floor to close; the in-house pass then found a program that passed every part of the rule and still read a live hot set, which is why the floor sits at 0.995 and not 0.98. What binds on v6: layer 4's test is a per-site ratio against the window model, and the window model is a function of the dataset size, the windows, the era stride and the read width, so a draw of any of those changes the null and the census must be re-derived per era (2.2 s per candidate at 2^20 on one box core; 0.7 percent of candidates refused at the floor); the residue the floor cannot reach without refusing most clean programs (the shadow-written concentrations at 0.9992 to 0.9997, about 1.0004x) moves with any draw of the shadow placement and needs its own ceiling per era, with the F8 gate's 1.2x-of-window shape.
## 4. The four layers against the history, layer by layer
### 4.1 Layer 1: per-era draws of the class parameters
What is declared: the parameters now fixed by release (the mixer round count within the tested margin, the op-mix weights within the measured safe band, the read width, the program length, the shadow placement) are drawn per era from chain state like the program. What the history says about each:
| Parameter drawn | The precedent | What the draw costs a chip | What it costs the honest card and the verifier | Reading |
|---|---|---|---|---|
| Mixer round count (within the tested margin) | RandomX made the item derivation itself a random program so a chip could not hard-wire it (SuperscalarHash); CryptoNight-R's random math raised chip latency 2.5x | nothing on the f = 1 chip (it derives no item); on the f = 0 recompute chip the fixed shape is the 3x factor, and a drawn ROUND COUNT keeps the shape: the chip builds the widest count and gates the rest | the verifier's 10 ms gate caps the count (x8 is 2.1 ms per warp on the reference core, x16 about 3.7); the daily build 23 to 77 ms at x8 | a draw of the count within a margin the chip already covers is firmware; the lever against the recompute chip is a drawn SHAPE (the 5 October addition 2, reserve), and the recompute chip is not the one anyone builds (chip-model-v3 5.6) |
| Op-mix weights (within the measured safe band) | X16R drew the ORDER of sixteen fixed hashes per block and an FPGA served it at 1.3x within 20 months; ProgPoW drew the math per period and no chip exists on its adopters in eight years, on small prizes | a sequencer chip over the twelve families covers any weight table; the measured GPU cost per family is the real constraint (shfl 55.8 pJ against add 11.3 on the 5090: a shuffle-heavy draw taxes the card up to 5x per instruction with no better k) | the per-program hash-rate spread must stay under the 5 percent rule on every vendor across the band (the six-era spread was 1.3 to 3.2 percent on the era layout) | right as a governance device (no fork), neutral as a chip device; the band must be bounded by the per-vendor cost table of `counter-asic-4-research.md` 15.1a, not only by the rate spread |
| Read width | w16 moved the honest denominator 2.7 percent and the chip's cost not at all; w64 made the 5090 bandwidth-bound (71.9 MH/s); the 9070 XT pays a 64-byte line at every width | the chip pays the same 32-byte atom at w4 and w16; wider reads hand a custom controller the Ren-Devadas bandwidth lever (the Ethash chips' whole edge) | a 47 percent loss on the 5090 at w64 | the one parameter whose draw can move the memory physics the wrong way: keep the allowed set at {1} (as 1.13.1 already does) unless a wider width is measured latency-bound on all three vendors; a draw over {4 B, 16 B} is harmless and worthless |
| Program length | ProgPoW's loop count and Ethash's 64 accesses were fixed; RandomX's 8 chained programs of 256 instructions fixed; no chain drew its program length | a longer program is more shadow work per hash: the class v4 lever (the latency ladder) priced at 2.1x at k = 1; a chip builds the longest rung's core and idles it on short eras | the verifier rung 3 is inadmissible on the reference core (latency-ladder section 5); the card's premium per op 6.2 to 11.3 pJ measured | the draw must stay inside the admissible rungs (0 to 2); its value is the governance one (the ladder stepped by draw instead of by 90 percent signal), and the honest card pays the premium on every era |
| Shadow placement | no precedent in any chain; the per-load placement (16 blocks of 16 after every load) was DEAD as drawn on 7 October (acceptance in execution order accepts 1.4 percent of candidates; `counter-asic-4-research.md` 20.2a-close) | the per-load form would force the chip's ALU core inside every read's dependency (the USD 200 M break-even row, 16.2) if a sound form existed | compile-ahead at 16 sites; a class change | draw only over placements shown sound (today: the one block after the loads); the per-load form is the research item, not a draw value |
### 4.2 Layer 2: the dataset's size tracking chain-state growth with a floor
What is declared: the state-derived dataset's size tracks chain-state growth, with a floor, so fixed-memory silicon ages out. The history has exactly two scheduled memory-growth rules that ran against shipped hardware, and one of them killed a chip:
| Precedent | The rule | What it did to chips | What it did to honest cards | Source |
|---|---|---|---|---|
| Ethash DAG growth | +8 MB per epoch of 30,000 blocks (about 0.7 GB a year; Rao's audit, slide "DAG size"); 1 GB at launch (July 2015), 3.0 GB by July 2019, 3.94 GB by November 2020 | the Antminer E3 (shipped July 2018, 4 GB of DDR3) ran out of DAG room on Classic at epoch 328 (about 3.56 GB, March 2020) and on Ethereum at about block 11.4 million (about October 2020) after a 30 March 2020 firmware stretched its DDR use: 20 to 27 months after shipping, 57 to 63 months after the hash went live; the A10 Pro (6 GB) and every later chip carried more memory than any card of its year and never aged out | the same rule retired 3 GB cards in 2018 and 4 GB cards by December 2020; Ethereum Classic cut the DAG to 2.47 GB (Thanos, ECIP-1099, block 11,700,000, 28 November 2020) to keep the 4 GB cards after the August 2020 51 percent attacks, and its own text says the fork kept "competitive mining across both GPU and ASIC hardware" | https://ethereumclassic.org/blog/2020-11-27-thanos-hard-fork-upgrade/ ; https://coingeek.com/memory-limitations-prompt-bitmain-antminer-e3-to-halt-etc-support/ ; https://cointelegraph.com/news/bitmains-antminer-e3-to-continue-mining-ether-with-new-update (all read 8 October 2026); Rao's audit, the DAG-size slide (https://github.com/ethcatherders/progpow-audit) |
| Autolykos v2 table growth | N = 2^26 elements of 31 bytes (2.08 GB) until block 614,400; then about 5 percent every 51,200 blocks (N doubles every 102,400 blocks, about 142 days at Ergo's 2-minute block) to a cap of 2,143,944,600 elements at block 4,198,400 (about 66 GB) | no chip has shipped for Autolykos as of today, on a small prize; the rule has never been tested against one | the table passes 8 GB in about 2 years of growth and 16 GB a year later (arithmetic on the rule); Ergo's GPU fleet thins by card memory on a schedule it chose | https://docs.ergoplatform.com/mining/autolykos/ (read 8 October 2026) |
The arithmetic that binds. A chip's memory is bought by the board, and today's prices are the chip model's: GDDR7 about USD 20 per 2 GB device, so 32 GB on a 512-bit board is USD 320; one HBM3 stack 24 GB about USD 200 (`chip-model-v3.md` 5.1, September to October 2026 prices). Igneum's schedule as specified (2 GiB plus 0.5 GiB a year, doubling steps at years 4, 12, 28; spec 1.13.3) reaches 4 GiB at year 4 and 8 GiB at year 12. Against that schedule:
| Memory the chip or card holds | Years until the dataset passes it | Who it is |
|---|---|---|
| 8 GB | 12 | the honest 8 GB card (the first tier out, `card-lifetime-2026-10-05.md`) |
| 12 GB | 20 | the honest 12 GB card |
| 16 GB | 28 | the 9070 XT class |
| 24 GB | 44 | one HBM3 stack; the 4090 and the M5 Max class |
| 32 GB | 60 | the f = 1 GDDR7 chip's board; the 5090 |
So layer 2 as a rate "tracking chain state" ages out fixed-memory silicon only if the dataset grows faster than a chip generation's memory headroom, and every rate that does that retires the honest small cards first by the same table. The E3 is the only case in the record where a growth rule beat a chip, and it beat a chip that had under-provisioned memory by a factor the card fleet also hit (4 GB). The rule that would hurt the f = 1 chip is one that keeps the dataset above what one board of commodity DRAM holds at the chip's price point, and that rule is unaffordable for the honest fleet. The honest reading: layer 2 is the right lever class (the memory is the one parameter a stored-dataset chip cannot read as firmware), and its value is set by the floor and the ceiling, not by the tracking: a floor keeps the dataset above every SRAM die (class B stays closed: 2 GiB is 1,000 mm^2 of SRAM even at N5), and a ceiling keeps it under the honest tiers' memory. Between those two lines the chip's board holds whatever the card holds, and the growth rate changes nothing for it. What "tracking chain state" adds over the fixed schedule is governance (no release decides the size) and the class v5 link (the dataset is built from the state, so the size follows the state's record count naturally); it is not an anti-chip rate. Open for the synthesis lane: if the chain's state grows the way Ethereum's did (approximate, from memory: Ethereum's account and storage state passed 100 GB in its eighth year), a dataset that tracks it literally outgrows every consumer card inside the chain's first decade, so the ceiling is the number to fix, in gigabytes per tier per year, before the rate.
### 4.3 Layer 3: scheduled family epochs by height, every 180 days, no release
What is declared: a new instruction family goes live on a height schedule, every 180 days by default, with no release (the reserve of spec 1.13.2, ordered at genesis). The record of scheduled change against chips:
| Chain | The change and its cadence | Human release needed | What it cost the chip | Outcome | Source |
|---|---|---|---|---|---|
| Grin, Cuckaroo lane | a new tweak of the edge function every six months (Cuckarood July 2019, Cuckaroom January 2020, Cuckarooz July 2020), each a hard fork; the lane's reward share scheduled from 90 percent to zero by January 2021 | yes, every time | a new edge function per tweak: a redesign, not a configuration | no chip ever shipped for the tweaked lane; the chip lane (Cuckatoo31+) got the iPollo G1 at about 4x in 23 months | the 5 October file rows 18 and 19, [S61] to [S66] |
| Monero | four algorithm forks in 20 months (v7 April 2018, v8 October 2018, CN-R March 2019, RandomX November 2019) | yes, every time | v7 and v8: a re-spin (85 percent of the hashrate vanished at v7 and chips were back at 85 percent four months after v8); CN-R: random math per block, chip latency up 2.5x; RandomX: a new class of machine, parity hardware after 46 months | the forks were events; the chips survived the ones that kept the shape and died on the one that changed the machine | rows 16 and 17; Vorick on a fork-surviving chip, [S47] |
| Ravencoin X16R | the ORDER of sixteen fixed hashes drawn per block from the previous block hash; no fork needed | no | nothing: a sixteen-core sequencer reads the order as a configuration | an FPGA at 1.3x within 20 months; the X16Rv2 fork (one hash swapped) was answered by bitstreams within weeks | row 9 |
| Ethereum ProgPoW | the random math re-drawn every PROGPOW_PERIOD (50 blocks in 0.9.2, 10 blocks in 0.9.3, about 2 minutes); the op set fixed (add, mul, mulhi, min, rotl, rotr, and, or, xor, clz, popcount) | no | a sequencer over the eleven ops and a 32-register file; the audit priced the conventional compute chip at little gain and the on-die cache chip at "<< 0.1x" energy per hash | never deployed on Ethereum; no chip on KawPow or FiroPoW in five to six years on small prizes | https://eips.ethereum.org/EIPS/eip-1057 and https://github.com/ifdefelse/ProgPOW (read 8 October 2026) |
| Igneum class v2 to v6 | a new program every epoch; era draws every 180 days; one reserve family per era | no | a recompile per epoch; the reserve families are in the shipped generator from genesis, so a chip that reads the reserve at genesis carries every family's datapath from day one | the governance failure is closed; the chip is not | this file |
The clocks that bound the race (all read 8 October 2026): Bitmain built the A3 "in about 5 months" and Halong the B52 "in about 9" (Vorick, through https://www.nextbigfuture.com/2018/05/obelisk-explains-the-state-of-asics-and-crypto-mining.html); KnC taped out a 20 nm part "only 3 months after starting the project" in 2014 (https://www.design-reuse.com/news/34090/20nm-asic-for-bitcoin-mining.html); ASICMiner went from founding in July 2012 to 64-chip boards on 31 January 2013 (Taylor, IEEE Computer 2017, https://michaeltaylor.org/papers/Taylor_Bitcoin_IEEE_Computer_2017.pdf); Linzhi from founding (February 2018) to tested boards (December 2020) took 27 months; Rao's 10 nm-class project "1+ year". A full Vivado compile on a mid-size Xilinx part (ZCU102) runs 42 minutes typical and 160 worst (PRflow, FPT 2019, https://ic.ese.upenn.edu/abstracts/prflow_fpt2019.html) and "several hours" on a large device (a 2021 Paderborn talk); the Least Authority audit called a 2-minute period "impractical" for a bitstream; the one KawPow FPGA on record is an academic VU35P build at 5.6 MH/s (NTU 2022, https://tdr.lib.ntu.edu.tw/handle/123456789/84103?locale=en), under an eighth of a 2022 GPU. So an hourly program outruns every compile and every design cycle; a 180-day family epoch outruns no chip's design cycle and does not need to, because the family is in the generator from genesis.
Reading. Scheduled change beat chips in exactly one shape: Grin's, where each change was a new function nobody could know in advance, and even then only because the lane was built to die. Every change a chip could read at genesis (X16R's order, ProgPoW's period, Igneum's reserve) became firmware. Layer 3 as declared is X16R's and ProgPoW's shape, automated and spaced at 180 days: it removes the fork (lesson 5 of the 5 October file, and the one thing that cost Vertcoin two 51 percent attacks), and it taxes a sequencer chip die area for families not yet live. The honest number for that tax is small: the reserve's candidates are integer ALU operations (shifts, bit-field extract, andn, byte permute, popcount, select, the second shuffle form; mm8 last), each a few thousand gates per lane; against the f = 1 chip's USD 470 of memory and board, a lane array carrying every reserve family is the same 30 mm^2 of N5 the class v4 shadow already forces (`counter-asic-4-research.md` 16.1: USD 25 to 40 of die). The one family that is not cheap for a chip to carry idle is one whose unit is large (mm8's tile engine), and that is exactly the family the measured rows say not to use for forcing (the 5090's int8 MAC at 1.4 to 4.1 pJ against a 5 nm array's claimed 0.04 to 0.4: `counter-asic-4-research.md` 15.1a). So layer 3 is right for governance and neutral for the chip; what would make a family epoch cost a chip a redesign is a family whose semantics are not knowable at genesis, which is the random item-derivation program of the 5 October addition 2 (a per-day SuperscalarHash-style derivation), the one RandomX idea Igneum has not taken, and it acts on the f = 0 chip only.
### 4.4 Layer 4: the (c''') floor and the F8-form uniformity test per era draw
What is declared: the (c''') acceptance floor (the per-site distinct-index ratio at or above 0.995 against the window model, spec 1.4.7.2) and the F8-form uniformity test generalised to each era's parameter draw, with a redraw on failure. The history has three attacks of this one class, and in every case the test that would have caught it lived outside the acceptance rule:
| Attack | The steer | Found when | What the fix was | Source |
|---|---|---|---|---|
| Kik's ProgPoW exploit (4 March 2020) | the 64-bit seed between the two keccak passes: fix a seed, compute its mix once, then grind nonces until keccak_progpow_64(header, nonce) equals the seed; the memory path is run once per 2^64 nonces, so a chip that never touches the DAG wins once the difficulty passes 2^50 | after two tentative approvals and five months after both audits (September 2019) | ProgPoW 0.9.4 widened the carried state from 64 to 256 bits (the digest of the first keccak, plus the mix, plus padding) | https://github.com/kik/progpow-exploit and https://github.com/ifdefelse/ProgPOW (read 8 October 2026) |
| Dinur and Nadler on MTP (2017) | the prover controls the memory's contents, so by injecting blocks it steers Argon2d's data-dependent addresses into a set it can hold in under 1 MB at a 170x compute penalty, in place of 2 GB | before launch, by cryptanalysis, not by the design's own test | MTP 1.2 patched the construction | the 5 October file [P18] [S38] |
| AP-F8-1 on class v4 (7 October 2026) | a load site whose source register was last written by a lossy op (or, mul, mulhi) saturates to all-ones or zero at a known rate, and the era map sends the constant to one item; 96.6 percent of class v4 programs carried a lossy-sourced load; the worst seed read 29x the window model on one item | in the attack-pass lane's census, one day after the class shipped to the devnet | sub-versions 1 to 3 (the freshness fixpoint, the executed shadow block, the (c'') ratio at 0.98), then class v5's (c''') at 0.995 | `docs/plans/counter-asic-3-status.md` section 7c; spec 1.4.7.2 |
Reading. Layer 4 is the right answer to this class and the only one of the four layers that acts on a mechanism the record shows beating hashes after launch. Two things bind on it. First, the test can only see what its null models: (c''') measures distinct-index ratios against the window model, which is a function of the dataset size, the per-site windows, the era stride and the read width; a draw of the read width or the program length changes the null, so "generalised to each era's draw" means the window model is re-derived per era and the census re-run per draw, not one floor reused. The cost is known: 2.2 s per candidate at 2^20 on one box core, once per epoch draw on a node, and 0.7 percent of candidates refused by the floor (spec 1.4.7.2). Second, the residue the floor cannot reach without refusing most clean programs is the shadow-block-written concentrations at 0.9992 to 0.9997, worth about 1.0004x to a chip (spec 1.4.7.2), and a per-era draw of the shadow placement moves that residue, so the redraw rule needs its own ceiling stated (the 1.2x-of-window gate of F8 is the right shape; the number per era is the census's to set). The Kik lesson is separate and already closed: Igneum's seed is 256 bits through the VDF and the program is the epoch's, so there is no 64-bit state to grind; the header-locality search (the 5 October check 1) remains the nearest analogue and was measured by adv-accept-2 in the in-house pass.
## 5. What to add, optimise or invent, ranked (first cut; the full report re-ranks with the other lanes' findings)
| Rank | What | Why the history says so | Cost to the honest card | Where |
|---|---|---|---|---|
| 1 | **State layer 2's floor and ceiling in gigabytes per tier, before its rate.** The floor above every SRAM die (today's 2 GiB holds); the ceiling under the honest tiers' memory on a stated glide (the 8 GB tier's life is the first number) | the E3 is the only chip a growth rule ever killed and it was the chip with the fleet's own memory limit; Scrypt-N was abandoned because its growth was public and slow; Autolykos's growth is untested; a dataset that tracks chain state literally outgrows every card if the state grows the way Ethereum's did (approximate) | none at the floor; everything at the ceiling | genesis rule, with the card-lifetime table |
| 2 | **The clock and the detector**, unchanged from the 5 October ranking and still unbuilt: the per-program rate spread and nonce pattern on the observer (the method that found Monero's chips at 85 percent), plus a share-by-key-and-template instrument (what found Qubic until it randomised), plus the issuance trigger at about USD 50 K a day | every chip in the record was on its chain before it was announced (Monero 2017, Zcash's three groups, SChernykh's 2021 reading of the X5) | none | before the public testnet |
| 3 | **Keep the read width out of the era draw** unless a width other than 4 bytes is measured latency-bound on all three vendors; a draw over {4 B, 16 B} is harmless and worthless (w16 moved the chip's cost not at all) | the Ethash chips' whole edge was the bandwidth lever Ren and Devadas name; w64 made the 5090 bandwidth-bound | a 47 percent loss on the 5090 at w64 | spec 1.13.1's allowed set stays {1} |
| 4 | **Bound the op-mix draw by the per-vendor energy table, not only by the rate spread**: the 5090 pays 55.8 pJ per shuffle against 11.3 per add, so a shuffle-heavy era taxes the honest card up to 5x per instruction for no better k | X16R's drawn order cost the chip nothing and the fleet nothing; Igneum's draw can cost the fleet watts | up to 2x the premium per instruction at the band's edge | the band's definition in the class v6 spec |
| 5 | **Order the reserve by what a sequencer cannot fold into firmware**, mm8 last; and name the random item-derivation program (the 5 October addition 2) as the one reserve item whose semantics are not knowable at genesis | the kHeavyHash chips and the 5090's own 1.4 to 4.1 pJ per int8 MAC; RandomX's SuperscalarHash is the one idea Igneum has not taken, and it acts on the f = 0 chip only | none at launch | reserve ordering, genesis |
| 6 | **Generalise layer 4 with a null per drawn parameter**: the window model re-derived per era, the census per draw, and a stated ceiling for the shadow-written residue per shadow placement | lesson 3 | 2.2 s per candidate once an epoch on a node | the class v6 acceptance rule |
| 7 | **The per-load shadow placement as a research item, not a draw value**, until a sound construction is drawn (the 16 x 27 form accepted 1.4 percent of candidates) | it is the one placement that would force the chip's ALU core inside every read's dependency (the USD 200 M break-even row) | compile-ahead at 16 sites | `counter-asic-4-research.md` 20.2a |
## 6. Consequences per user tier
| Tier | What this history means for it | What is being done |
|---|---|---|
| Home miner, one 8 GB card | Layer 2 is the one layer whose rate reaches this tier first: at 0.5 GiB a year the 8 GB card is out at year 12, and any rate fast enough to age out a 32 GB chip board is out of this card's life inside two years. No chip of class A, B or E touches this miner under v6; the class C chip (the memory system without the GPU) reaches it as it reached Ethash's 4 GB miners: by price per MH/s, 5x | the layer 2 ceiling stated per tier (section 4.2) before the rate; the issuance clock and the detector (section 5) |
| One 12 GB or 16 GB card | as the 8 GB tier with 20 and 28 years on the schedule; the 9070 XT's 10.6 microjoules per hash is 23x behind the GDDR7 chip per joule on the model, so this tier's card is the first the class C chip displaces | nothing in the hash fixes AMD's dependent-read rate; the vendor-share metric is the warning |
| One 24 or 32 GB card (5090, M5 Max) | the honest best: 1.69 microjoules at the 5090's knee against the chip's 0.47; 3.6x at zero premium, 2.1x with the shadow at k = 1; the M5 Max at 0.78 microjoules is 1.7x behind the GDDR7 chip with no shadow at all | the operating point as the shipped default (Ember); the shadow's rung |
| A rig | the Ethash precedent in full: chips at 2x to 5x per joule and 5x per dollar took the hashrate over four years, and the ASIC share stayed small only while the chips were not cheap enough at scale; the model says this chip is (USD 2.8 against 14.7 per MH/s) | the break-even cap row (USD 100 M in years 1 to 2 with the N5 shadow core) is the real wall; the clock |
| A pool user | MoneroCrusher found chips at 85 percent of Monero's hashrate by the share pattern, four months after a fork; Igneum's detector is the same method on the observer, unbuilt | the detector before the public testnet (section 5) |
| Every tier, on governance | no fork, ever, for a draw or a family: the history's clearest lesson (Vertcoin's two 51 percent attacks after forks, Monero's four, Ethereum's two-year ProgPoW fight) is the one v6's layers 1 and 3 close outright | nothing further |
## 7. Unverified and owed
- The research lanes' returns for the chip mechanism columns (section 1 and 2) are the first cut's owed content; where a lane reports "not found" the row says so and carries the 5 October file's figure.
- The Vorick post (13 May 2018) is read through secondary coverage (davidgerard.co.uk, zycrypto.com, nextbigfuture.com, a steemit copy; read 8 October 2026): the secret-Monero-ASIC claim ("since early 2017, making up 50 percent of the hashrate"), the three Zcash groups, the Equihash fork-following architecture, "about 5 months" for Bitmain's A3 and "about 9 months" for Halong's B52, the A3 under USD 10 M with USD 20 M of orders in eight minutes, the manufacturer withdrawal that cost Obelisk "north of USD 2 million". The 5 October file's "13 months for a startup" and "a chip able to survive Monero's forks at under a 5x hit" were NOT found on any fetched page and are carried here as unverified; the Monero fork-survival fact that is verified is the record itself (chips back inside four months of v8).
- The KawPow fork block and its 3-block period are approximate (the minerstat and Tron Black pages answered 403).
- The Ethereum DAG date of passing 4 GB on the main chain (about December 2020) is approximate; the Classic figures (3.94 GB at epoch 376, 27 November 2020) are cited.
- The Ethereum state-size figure in section 4.2 is from memory, approximate, and is the open question handed to the synthesis lane.
- Every per-joule ratio for a chip against a GPU is arithmetic on the cited rate and watt figures of both and is approximate by construction.
- Nothing here is a measurement; the Igneum figures are the repo's measured rows as cited, and the chip figures are the chip model's, modelled.
## 8. Sources
Every URL is cited inline at the row that uses it, with "read 8 October 2026" at the row or the section; the 5 October file's [S], [P], [E] and [L] lists are cited by their tags and not repeated. The primary documents read in full by this lane (text extracted where the page is a PDF): EIP-1057 (https://eips.ethereum.org/EIPS/eip-1057); the ifdefelse ProgPOW README (https://github.com/ifdefelse/ProgPOW); the Least Authority audit (https://leastauthority.com/static/publications/LeastAuthority-ProgPow-Algorithm-Final-Audit-Report.pdf, report version 9 September 2019); Bob Rao's hardware audit (https://github.com/ethcatherders/progpow-audit, 6 September 2019); Kik's exploit (https://github.com/kik/progpow-exploit); RandomX design.md, design_v2.md, specs.md, PR 317, release v2.0 and issue 11 (https://github.com/tevador/RandomX); Tromp's README and the Grin forum threads named in 2.4 (https://github.com/tromp/cuckoo ; https://forum.grin.mw); the Ergo Autolykos docs (https://docs.ergoplatform.com/mining/autolykos/); the Thanos post (https://ethereumclassic.org/blog/2020-11-27-thanos-hard-fork-upgrade/); the TechInsights Jasminer notes (https://www.techinsights.com/ko/node/51986 and /52149); the Fudan NDSS 2019 paper (https://www.ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_09-5_Bai_paper.pdf); Percival's lookup-gap note (https://mail.tarsnap.com/scrypt/msg00092.html); Lee and Kim on Qubic (https://arxiv.org/html/2512.01437v2); PRflow (https://ic.ese.upenn.edu/abstracts/prflow_fpt2019.html). Papers of 2024 to 2026 found: Blocki and Smearsoll, "Provably memory-hard proofs of work with memory-easy verification", ePrint 2025/1456 (Omega(N^2 / log N) cumulative memory with polylog verification: https://eprint.iacr.org/2025/1456); Condrey, PoSME, arXiv 2604.15751; Yang et al., PHICOIN, arXiv 2412.17979 (a resistance claim with no algorithm in the abstract). Pages that refused every lane (403, 404, DNS): Vorick's original post on Medium and sia.tech and its archive copy; Linzhi's and ifdefelse's Medium posts; MoneroCrusher's Medium post (figures taken from criptonoticias coverage); bitmain.com's product list; support.bitmain.com's Z9 page; minerstat; Tron Black's posts; innosilicon.global; jasminer.com (an empty shell); cryptomining-blog.com; the Yole DBI report. The session's web-search budget ran out at 11:0x UK; everything after that is direct fetches of known URLs, and "not found" in this file means not found on a fetched page.