diff --git a/docs/commercial/prover-customer-brief.md b/docs/commercial/prover-customer-brief.md index e63b2ceb..be77fb48 100644 --- a/docs/commercial/prover-customer-brief.md +++ b/docs/commercial/prover-customer-brief.md @@ -11,7 +11,7 @@ A proof-of-work chain mined on consumer GPUs, where the same cards prove every I | Item | What it is | Status today | |---|---|---| | Proofs for your chain | Your batches or blocks proven by Igneum's GPU prover network and returned to the address you name | Designed. No shard has been proven on a card yet | -| Price in dollars | Jobs are priced in dollars per proof. At launch the fee is paid on your own chain, in your currency, to a payout contract keyed by miner address, because Igneum cannot yet see your chain. Settlement in the coin follows when the proof bridge exists | Spec section 5.4 | +| Price in dollars | Jobs are priced in dollars per proof, at or above the subsidy the prover forgoes while it proves, which is a formula with network hash as the input, never a fixed number: per shard, (card hash ÷ network hash) × 0.8 × 31.688 IGN × shard seconds, plus electricity (under a cent per billion cycles on every card). The price falls as one over network hash: at the devnet's 1.16 GH/s a quote is 100 to 300x the published market rate, and a card proving beside its miner is competitive near 100 GH/s (the Horizon economy lane, `docs/analysis/horizon/economy-and-utility.md` sections 3.1 and 4.1, 6 October 2026; approximate beyond the one card measured; ledger E20). At launch the fee is paid on your own chain, in your currency, to a payout contract keyed by miner address, because Igneum cannot yet see your chain. Settlement in the coin follows when the proof bridge exists | Spec section 5.4 | | Delivery rule | A job is claimed with a bond that is slashed on a late or bad proof; a job nobody proves by its deadline expires and refunds in full. At launch your chain's own bond and slashing apply to the miner who claimed the job | Design document, execution layer, sections 5.2 and 6. Bond size and timeout are open (O-5.6) | | A versioned interface | Jobs run against the `ProofSystem` trait, version 1 of which is SP1. A later version is a release with its own test-vector set and a three-month overlap, so your integration survives a prover swap | Design document, execution layer, section 5.6 | | Verification you can run | A job proof is a single proof your contract verifies on your own chain; Igneum's own segment proofs recursively verify it, so no relayer or committee is in the path | Designed | @@ -25,7 +25,7 @@ One row per route, so operator income and protocol income never blur. Rows 1 to | 1. Emission, per block | IGN, new coins on the published schedule | 80% the block's miner, 20% the proving pool for the provers of that block | None | None. Implemented in consensus on the devnet | | 2. Base fee, both gas dimensions | IGN | Nobody | The base fee the chain sets per block | All of it. Implemented on the devnet | | 3. Priority fee | IGN | 80% the block's miner and provers; 20% the apps whose code ran, per call frame | The tip the sender sets | The share of any frame in an unregistered contract. Implemented on the devnet | -| 4. External job, at launch | Your currency, on your chain | The miner who delivered, through a payout contract keyed by miner address | Priced in dollars per proof; your chain's own bond and slashing apply | None; Igneum cannot see the payment. Designed | +| 4. External job, at launch | Your currency, on your chain | The miner who delivered, through a payout contract keyed by miner address | Priced in dollars per proof, at or above the subsidy the prover forgoes (the formula in network hash in the "Price in dollars" row, never a fixed number); your chain's own bond and slashing apply | None; Igneum cannot see the payment. Designed | | 5. External job, after the proof bridge | IGN, on Igneum | 90% the provers who delivered | The job fee | 10%. Designed, phase two | | 6. The official client's dev fee | IGN | The project, as operator income, never the protocol | 1 block template in 100 requested with the dev address; off with one flag | None. Implemented, measured on a test network 4 October 2026 | diff --git a/docs/fud-ledger.md b/docs/fud-ledger.md index 60fae6e9..f74cfef2 100644 --- a/docs/fud-ledger.md +++ b/docs/fud-ledger.md @@ -449,6 +449,24 @@ Sweep (5 October 2026, evening): stated. `site/litepaper.html`, Economics first --- +### P24. "20 percent of emission to provers" without the caveat that consensus does not verify the proof +"Your 20 percent pays whoever submits a proof record whose statement matches the node's own execution. The node never checks the SP1 proof behind it. So the block producer, who writes the record, can claim shard pay with a false proof today, in proportion to its hash. Say so next to the 20 percent." + +Status: Conceded, stated (6 October 2026, evening; the Horizon security lane `docs/analysis/horizon/consensus-security.md` finding 3 and its proposal 1): `site/litepaper.html`, Economics, the 20% proving-pool row carries the caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a block producer could claim shard pay with a false proof (ledger P21; the in-consensus verifier is the 0.3.16 fix). + +Answer: Correct; it is P21's finding read from the payer's side. The fix is the security lane's proposal 1: a record whose aggregated segment proof does not verify against the pinned aggregator key is invalid in consensus; the per-shard v0 record stays payout-only until then and is capped at the exclusive window. Consequence per tier: no honest miner loses anything today, since the pool is paid per valid record and the devnet's producers are the project's; the risk is a dishonest producer at the public testnet, which is why the fix lands in 0.3.16, before it. + +Evidence: `docs/analysis/horizon/consensus-security.md` finding 3 and proposal 1, 6 October 2026; spec 07 7.7 item 4 and 7.8 item 8; ledger P21. + +### P25. Unclaimed pool credit is stranded in the escrow +"Spec 5.3 pays the first valid proof included in a block; 7.7 refuses a record older than 600 chain blocks; 7.8 says an unproven segment's aggregator share stays in the escrow. Nothing says what happens to the shard credit nobody claims. It sits there for ever. A ten-day refusal strands millions of IGN." + +Status: Conceded, stated (6 October 2026, evening; the Horizon economy lane `docs/analysis/horizon/economy-and-utility.md` section 4.2 and proposal 2): `site/litepaper.html`, Economics, the 20% proving-pool row carries the note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven segment's pool (0.3.16). + +Answer: Correct. The lane's simulation puts a ten-day refusal at 5.5 M IGN stranded (section 4.2: the pool share paid falls to 0.67 with 0.33 stranded during the refusal, 182,387 IGN a day averaged); the devnet already burns the coinbase's 20% output at an unspendable script, so nothing is lost that was ever claimable today. The rule: an unproven shard's credit rolls forward into the next proven segment's pool instead of sitting in the escrow. Consequence per tier: a prover sees a larger pool after a refusal instead of a smaller one; nothing changes for a miner or a pool user. + +Evidence: `docs/analysis/horizon/economy-and-utility.md` section 4.2 (the stranded share) and proposal 2, 6 October 2026; spec 5.3, 7.7 item 3, 7.8 item 7. + ## 4. Economics and the coin ### E1. Hard cap plus burn is a security budget cliff @@ -538,6 +556,24 @@ Answer: Correct. The whole public proving market is three to four orders of magn Evidence: `docs/analysis/horizon/frontier.md` section 3.11 and the summary (section 7), 6 October 2026; the tracker (ethproofs, "sub-half-cent" fields, September 2026, secondary); the emission schedule (31.688 IGN a block in year 1). +### E20. "Proofs at the cost of power" is the electricity, not the price +"Your cards' electricity is cheap, fine. The price a prover must charge is the lottery income it gives up while it proves, and that scales as one over the network's hash. At your devnet's 1.16 GH/s every quote is a hundred times the market. 'Marginal cost close to power' and 'priced in dollars per proof' are both unconditioned." + +Status: Conceded, stated (6 October 2026, evening; the Horizon economy lane `docs/analysis/horizon/economy-and-utility.md` sections 3.1 and 4.1, proposal 3): `site/litepaper.html`, The problem ("a supplier whose electricity cost is close to power and whose price is the subsidy it forgoes, which falls as the network's hash grows"), Building on Igneum ("Proofs priced by the subsidy forgone", with the price as a formula in network hash: per shard, card hash over network hash x 0.8 x 31.688 IGN x shard seconds, plus electricity; 100 to 300x the published market rate at 1.16 GH/s, competitive near 100 GH/s beside the miner, approximate beyond the one card measured), the payment-routes row 4 ("at or above the subsidy the prover forgoes ... never a fixed number"), For miners, Economics and the questions list. The price is published as a formula, never a number. Supersedes P6's stated sentence ("a supplier whose marginal cost is close to power"), which the text check now carries in the conditioned form. + +Answer: Correct. Electricity is under a cent per billion cycles on every card; the price is `h/N` x the subsidy per shard. At 100 GH/s a card proving alone is at 1 to 3x the published market and a card beside its miner at 0.2 to 0.4x, the only row where Igneum undercuts the market, and it rests on the 4% hash loss measured on one card. Consequence per tier: at launch a home miner earns more hashing than proving for outsiders at any card size; a rig the same; the proving market is upside for the fleet as a whole only as network hash grows. + +Evidence: `docs/analysis/horizon/economy-and-utility.md` sections 3.1 (the cost model), 4.1 (the table per card and scale) and proposal 3, 6 October 2026; the Boundless median of USD 0.21 per billion cycles (`developer-adoption.md` 2b, approximate). + +### E21. The dev fee is 1 percent of the producer share, and the funding plan's ceiling took all rewards +"Your funding plan says the 1 percent fee could be USD 48,000 to 963,000 a year on year-one rewards of 963 million IGN. The fee template only moves the producer payout. The pool is paid per record. Your ceiling is a quarter too high, and the litepaper never says which share the fee is of." + +Status: Conceded, stated (6 October 2026, evening; the Horizon economy lane `docs/analysis/horizon/economy-and-utility.md` section 4.4 and proposal 7): `site/litepaper.html`, the payment-routes row 6 and the Ember section read "default-on, switchable, 1 percent of the producer share"; `docs/plans/funding.md` section 4's ceiling is 1 percent of the producer share, USD 38,520, 154,080 and 770,400 a year at USD 0.005, 0.02 and 0.10 per IGN with every miner on the official client, corrected from 48,000, 193,000 and 963,000. + +Answer: Correct. The fee block carries the dev address in the producer output only; the 20% pool output and the per-record escrow are untouched, so the fee's base is 80% of emission. Consequence per tier: a miner on Ember with the fee on gives up 1 in 100 of its own block rewards and nothing of its proving pay; off with one flag, the same on every tier. + +Evidence: `docs/analysis/horizon/economy-and-utility.md` section 4.4 (`devfee_out.md`) and proposal 7, 6 October 2026; the fee measured on a test network, 4 October 2026 (bench-log: 9 fee blocks in 785). + ## 5. Governance and the founders ### G1. No cryptography team @@ -626,6 +662,15 @@ Evidence: design doc Finality v2, Residual risks bullet 3. --- +### G15. Three signalling thresholds, four numbers across the documents +"Spec 5.7 says 90 percent for an upgrade, 5.5 says 60 percent for a parameter, the class-change rule says 95 with a floor, the project rules file says 90 and 60, and the litepaper's Mining section says a 90 percent signal turns a spare defence on, which is a class change your own rule sets at 95. Pick one sentence and put it everywhere." + +Status: Conceded, stated (6 October 2026, evening; the Horizon economy lane `docs/analysis/horizon/economy-and-utility.md` proposal 4, lane 3's signalling results): one sentence in `site/litepaper.html`, Governance ("Miners set what genesis leaves open") and Mining ("Miners hold the switch"): miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. The project rules file carries the same sentence (the coordinator's commit of 6 October 2026). Spec 5.5 (60) and 5.7 (90) agree with it; the 95-with-floor rule is the class v4 cut's P2 rule. + +Answer: Correct. The three numbers are three different things: a parameter is a dial inside rules genesis fixed, an upgrade is new code every node must run, a class change moves the hash itself and so takes the highest bar with a floor height as the backstop against a holdout. The lane's game (section 4.3): a 6 percent holdout costs near zero and buys only delay to the floor; a 30 percent pool holds a veto over upgrades at 90 and over class changes until the floor. + +Evidence: `docs/analysis/horizon/economy-and-utility.md` section 4.3 and proposal 4, 6 October 2026; spec 5.5, 5.7, 5.8; the class v4 cut's status file (gates P1 and P2). + ## 6. Comparisons ### C1. vs Monero: GPUs were excluded on purpose diff --git a/docs/plans/funding.md b/docs/plans/funding.md index 50f00583..88a920b0 100644 --- a/docs/plans/funding.md +++ b/docs/plans/funding.md @@ -55,7 +55,7 @@ The unfunded half is the half that comes after the chain exists and before and j ## 4. What the 1% fee could be, and why it is not counted -The fee is 1% of rewards on the official client. Rewards in year one are 963 million IGN (ramp included, `docs/analysis/security-budget.md`). At the low, base and high price inputs of that analysis the fee's ceiling, with every miner on the official client, is USD 48,000, 193,000 and 963,000 a year. Those are inputs, not expectations, and the share of miners on the official client is unknown. Nothing in section 2 is funded against them. +The fee is 1% of the producer share on the official client, default on and switchable: the fee template moves only the producer payout (80% of emission), and the proving pool is paid per record and carries none of it. Rewards in year one are 963 million IGN (ramp included, `docs/analysis/security-budget.md`), so the producer share is 770 million. At USD 0.005, 0.02 and 0.10 per IGN the fee's ceiling, with every miner on the official client, is USD 38,520, 154,080 and 770,400 a year (corrected 6 October 2026 from 48,000, 193,000 and 963,000, which took 1% of all rewards and overstated the ceiling by a quarter; the Horizon economy lane, `docs/analysis/horizon/economy-and-utility.md` section 4.4). Those are inputs, not expectations, and the share of miners on the official client is unknown. Nothing in section 2 is funded against them. ## 5. Rules diff --git a/site/ledger.html b/site/ledger.html index 7b35d0f3..dc0f3b5b 100644 --- a/site/ledger.html +++ b/site/ledger.html @@ -4,13 +4,13 @@ Igneum ledger: every criticism, answered - + - + @@ -18,7 +18,7 @@ - + @@ -134,20 +134,20 @@ details{margin-top:8px;font-size:14px;color:var(--ash)}summary{cursor:pointer;co
-
Ledger · 171 entries · regenerated from the repository
+
Ledger · 176 entries · regenerated from the repository

Every criticism, answered or conceded

-

This is every criticism the project expects, in the critic's words, with what was done about it and the date. 171 entries since 3 October 2026. Entries are never deleted; a status that changes keeps its history on the line. Where the critic was right the entry says Conceded. Where nothing has been done it says Open and names what settles it. The founder mined through the GPU years. Ethereum's move to proof of stake in September 2022 ended that income and the miners' place in that chain. This is one person building, with AI systems doing the engineering, the coin he wanted to exist for miners: GPU-mined, the miners are the provers, no founder allocation, every cost stated. Help is welcome and a team is wanted: cryptographers, node engineers, miners who will test. This ledger is the application form: pick an open row and write to hello@igneum.network with its id.

+

This is every criticism the project expects, in the critic's words, with what was done about it and the date. 176 entries since 3 October 2026. Entries are never deleted; a status that changes keeps its history on the line. Where the critic was right the entry says Conceded. Where nothing has been done it says Open and names what settles it. The founder mined through the GPU years. Ethereum's move to proof of stake in September 2022 ended that income and the miners' place in that chain. This is one person building, with AI systems doing the engineering, the coin he wanted to exist for miners: GPU-mined, the miners are the provers, no founder allocation, every cost stated. Help is welcome and a team is wanted: cryptographers, node engineers, miners who will test. This ledger is the application form: pick an open row and write to hello@igneum.network with its id.

- + - +
CountStatusMeaning
7Nothing has settled it yet. The entry names what will
57The critic is right. "Stated" means the public text says so; "not yet stated" means it does not yet
62The critic is right. "Stated" means the public text says so; "not yet stated" means it does not yet
54A code, spec or text change answers it, with the commit or the page named
27A consensus rule or a decision by the owner answers it, dated
13A measurement or a simulation exists and is named
13A design rule answers it; no measurement is possible yet
171Every entry. The sections: Mining and chips, Finality and attacks, Proving and the zkEVM, Economics and the coin, Governance and the founders, Comparisons, Legal and regulatory, Launch and operations, Builders
176Every entry. The sections: Mining and chips, Finality and attacks, Proving and the zkEVM, Economics and the coin, Governance and the founders, Comparisons, Legal and regulatory, Launch and operations, Builders

Mining and chips

@@ -387,6 +387,18 @@ details{margin-top:8px;font-size:14px;color:var(--ash)}summary{cursor:pointer;co
Conceded, stated 5 October 2026, night): a repository file, Economics, "Outside customers pay in their own currency on their own chain at launch; settlement in IGN with a 10% burn follows when the proof bridge lets Igneum see the payment"; the route table rows 4 and 5 (E13). Was: Conceded, contradiction to fix.
The answer as first written

The litepaper contradicts itself. The design is: at launch external jobs are paid on the customer's chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum. The 10% burn in IGN applies when the job market settles on Igneum, which needs the proof bridge. The Economics section must say so.

+
+
P24

"20 percent of emission to provers" without the caveat that consensus does not verify the proof

6 October 2026
+
Your 20 percent pays whoever submits a proof record whose statement matches the node's own execution. The node never checks the SP1 proof behind it. So the block producer, who writes the record, can claim shard pay with a false proof today, in proportion to its hash. Say so next to the 20 percent.
+
Conceded, stated 6 October 2026, evening; the Horizon security lane a repository file finding 3 and its proposal 1): a repository file, Economics, the 20% proving-pool row carries the caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a block producer could claim shard pay with a false proof (ledger P21; the in-consensus verifier is the 0.3.16 fix).
+
The answer as first written

Correct; it is P21's finding read from the payer's side. The fix is the security lane's proposal 1: a record whose aggregated segment proof does not verify against the pinned aggregator key is invalid in consensus; the per-shard v0 record stays payout-only until then and is capped at the exclusive window. Consequence per tier: no honest miner loses anything today, since the pool is paid per valid record and the devnet's producers are the project's; the risk is a dishonest producer at the public testnet, which is why the fix lands in 0.3.16, before it.

+
+
+
P25

Unclaimed pool credit is stranded in the escrow

6 October 2026
+
Spec 5.3 pays the first valid proof included in a block; 7.7 refuses a record older than 600 chain blocks; 7.8 says an unproven segment's aggregator share stays in the escrow. Nothing says what happens to the shard credit nobody claims. It sits there for ever. A ten-day refusal strands millions of IGN.
+
Conceded, stated 6 October 2026, evening; the Horizon economy lane a repository file section 4.2 and proposal 2): a repository file, Economics, the 20% proving-pool row carries the note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven segment's pool (0.3.16).
+
The answer as first written

Correct. The lane's simulation puts a ten-day refusal at 5.5 M IGN stranded (section 4.2: the pool share paid falls to 0.67 with 0.33 stranded during the refusal, 182,387 IGN a day averaged); the devnet already burns the coinbase's 20% output at an unspendable script, so nothing is lost that was ever claimable today. The rule: an unproven shard's credit rolls forward into the next proven segment's pool instead of sitting in the escrow. Consequence per tier: a prover sees a larger pool after a refusal instead of a smaller one; nothing changes for a miner or a pool user.

+

Economics and the coin

E1

Hard cap plus burn is a security budget cliff

3 October 2026
@@ -442,6 +454,18 @@ details{margin-top:8px;font-size:14px;color:var(--ash)}summary{cursor:pointer;co
Conceded, stated 6 October 2026, evening; the Horizon lane analysis a repository file section 3.11, frontier_model.py section 7): a repository file, "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block x 7,200 blocks; the tracker figure is a secondary source) against about USD 13,700 a day of Igneum's year-1 emission at USD 0.005 per IGN (31.688 IGN a block x 86,400; the price is an input, not a forecast), so external proving is a small second income at launch and the lottery pays the bills; paid demand would have to grow about 1,000x in dollars for proving to become the main income. Figures the lane labels approximate (all rollup proving spend, USD 8,200 to 27,400 a day; Boundless's trailing day, USD 2) are not on the page.
The answer as first written

Correct. The whole public proving market is three to four orders of magnitude under year-1 emission at any price input (the lane's table: Ethereum L1 at the Sep 2026 cost USD 36 a day, at the Dec 2025 cost 288; year-1 emission 13,700 at USD 0.005, 54,800 at 0.02, 273,800 at 0.10). The cost curve falls 3x to 30x a year, so dollars per proof fall as fast as volume rises. The design's own claim stays the defensible one: a second income that keeps cards on after the subsidy fades (spec 5.10.2), never the main one by 2030.

+
+
E20

"Proofs at the cost of power" is the electricity, not the price

6 October 2026
+
Your cards' electricity is cheap, fine. The price a prover must charge is the lottery income it gives up while it proves, and that scales as one over the network's hash. At your devnet's 1.16 GH/s every quote is a hundred times the market. 'Marginal cost close to power' and 'priced in dollars per proof' are both unconditioned.
+
Conceded, stated 6 October 2026, evening; the Horizon economy lane a repository file sections 3.1 and 4.1, proposal 3): a repository file, The problem ("a supplier whose electricity cost is close to power and whose price is the subsidy it forgoes, which falls as the network's hash grows"), Building on Igneum ("Proofs priced by the subsidy forgone", with the price as a formula in network hash: per shard, card hash over network hash x 0.8 x 31.688 IGN x shard seconds, plus electricity; 100 to 300x the published market rate at 1.16 GH/s, competitive near 100 GH/s beside the miner, approximate beyond the one card measured), the payment-routes row 4 ("at or above the subsidy the prover forgoes ... never a fixed number"), For miners, Economics and the questions list. The price is published as a formula, never a number. Supersedes P6's stated sentence ("a supplier whose marginal cost is close to power"), which the text check now carries in the conditioned form.
+
The answer as first written

Correct. Electricity is under a cent per billion cycles on every card; the price is h/N x the subsidy per shard. At 100 GH/s a card proving alone is at 1 to 3x the published market and a card beside its miner at 0.2 to 0.4x, the only row where Igneum undercuts the market, and it rests on the 4% hash loss measured on one card. Consequence per tier: at launch a home miner earns more hashing than proving for outsiders at any card size; a rig the same; the proving market is upside for the fleet as a whole only as network hash grows.

+
+
+
E21

The dev fee is 1 percent of the producer share, and the funding plan's ceiling took all rewards

6 October 2026
+
Your funding plan says the 1 percent fee could be USD 48,000 to 963,000 a year on year-one rewards of 963 million IGN. The fee template only moves the producer payout. The pool is paid per record. Your ceiling is a quarter too high, and the litepaper never says which share the fee is of.
+
Conceded, stated 6 October 2026, evening; the Horizon economy lane a repository file section 4.4 and proposal 7): a repository file, the payment-routes row 6 and the Ember section read "default-on, switchable, 1 percent of the producer share"; a repository file section 4's ceiling is 1 percent of the producer share, USD 38,520, 154,080 and 770,400 a year at USD 0.005, 0.02 and 0.10 per IGN with every miner on the official client, corrected from 48,000, 193,000 and 963,000.
+
The answer as first written

Correct. The fee block carries the dev address in the producer output only; the 20% pool output and the per-record escrow are untouched, so the fee's base is 80% of emission. Consequence per tier: a miner on Ember with the fee on gives up 1 in 100 of its own block rewards and nothing of its proving pay; off with one flag, the same on every tier.

+

Governance and the founders

G1

No cryptography team

5 October 2026
@@ -491,6 +515,12 @@ details{margin-top:8px;font-size:14px;color:var(--ash)}summary{cursor:pointer;co
Conceded, stated in the design doc
The answer as first written

True in the same way it is true on Bitcoin, where miner signalling activated SegWit and Taproot. The thresholds are high so that nothing passes without near-consensus. Since 3 October 2026 there is no fund to spend: the 60% threshold applies only to parameters that the genesis rules leave to miners, and 90% to upgrades. The litepaper should name pool concentration as the governance risk rather than imply every miner votes.

+
+
G15

Three signalling thresholds, four numbers across the documents

6 October 2026
+
Spec 5.7 says 90 percent for an upgrade, 5.5 says 60 percent for a parameter, the class-change rule says 95 with a floor, the project rules file says 90 and 60, and the litepaper's Mining section says a 90 percent signal turns a spare defence on, which is a class change your own rule sets at 95. Pick one sentence and put it everywhere.
+
Conceded, stated 6 October 2026, evening; the Horizon economy lane a repository file proposal 4, lane 3's signalling results): one sentence in a repository file, Governance ("Miners set what genesis leaves open") and Mining ("Miners hold the switch"): miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. The project rules file carries the same sentence (the coordinator's commit of 6 October 2026). Spec 5.5 (60) and 5.7 (90) agree with it; the 95-with-floor rule is the class v4 cut's P2 rule.
+
The answer as first written

Correct. The three numbers are three different things: a parameter is a dial inside rules genesis fixed, an upgrade is new code every node must run, a class change moves the hash itself and so takes the highest bar with a floor height as the backstop against a holdout. The lane's game (section 4.3): a 6 percent holdout costs near zero and buys only delay to the floor; a 30 percent pool holds a veto over upgrades at 90 and over class changes until the floor.

+

Comparisons

C1

vs Monero: GPUs were excluded on purpose

3 October 2026
diff --git a/site/litepaper.html b/site/litepaper.html index 4b67e57e..141d3510 100644 --- a/site/litepaper.html +++ b/site/litepaper.html @@ -258,7 +258,7 @@ body.all .pager{display:none}

Rollups, bridges and soon Ethereum itself need zero-knowledge proofs of every batch and every block. Today those proofs come from a few private GPU clusters run by the rollup teams or by a handful of proving companies. The work is a commodity, a proof is correct or it is not, and the cheapest correct proof should win. It does not, because the people with the cheapest GPUs are not in the market.

Small proof-of-work chains get attacked

When rental markets can hire more hashrate than a chain has for an hour, double-spends against exchanges are cheap. Ethereum Classic, Bitcoin Gold and Vertcoin were all hit this way. Every one of them let hashrate that appeared a minute ago rewrite history.

-

Igneum gives the GPU fleet paid, useful, verifiable work. It gives the proving market a supplier whose marginal cost is close to power. And it makes the right to rewrite history something that must be earned over a month of public mining, not rented for an hour.

+

Igneum gives the GPU fleet paid, useful, verifiable work. It gives the proving market a supplier whose electricity cost is close to power and whose price is the subsidy it forgoes, which falls as the network's hash grows. And it makes the right to rewrite history something that must be earned over a month of public mining, not rented for an hour.

@@ -343,7 +343,7 @@ body.all .pager{display:none} ContinuouslyThe dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. A chip is built with fixed memory, so it is on a countdown from the day it ships. Ethereum's growing dataset ran Bitmain's E3 out of memory in 2020 this way, approximate, with nobody doing anythingNo -

Three ideas carry the chip resistance. The hash rewrites itself. A new program every hour, drawn from the chain. Its memory pattern changes with it. The rules change on a schedule fixed at launch. No release, no vote. These are automatic schedule changes: they defeat a chip wired for one datapath and they need no human fork. Against a chip that stores the dataset every drawn parameter is firmware, and what meets that chip is the latency-shadow work (class v4) and the price per joule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). It waits on memory, not maths. Every hash is a chain of random reads into a table too big for a chip to carry. The wait is the same physics for everyone. Miners hold the switch. Spare defences are written into the rules, switched off. A 90% miner signal turns one on. No fork.

+

Three ideas carry the chip resistance. The hash rewrites itself. A new program every hour, drawn from the chain. Its memory pattern changes with it. The rules change on a schedule fixed at launch. No release, no vote. These are automatic schedule changes: they defeat a chip wired for one datapath and they need no human fork. Against a chip that stores the dataset every drawn parameter is firmware, and what meets that chip is the latency-shadow work (class v4) and the price per joule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). It waits on memory, not maths. Every hash is a chain of random reads into a table too big for a chip to carry. The wait is the same physics for everyone. Miners hold the switch. Spare defences are written into the rules, switched off. A miner signal turns one on, at the class-change threshold: miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. No fork.

No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the response takes a week, and both are measured. The model is public: the numbers; the claim is tested by paid independent cryptanalysis and the public benchmark. Monero has run on RandomX since 2019 with no chip publicly shipped, approximate; that is precedent, not proof.

One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.

@@ -405,7 +405,7 @@ body.all .pager{display:none}

Why build here

Not for speed. Fast EVM chains filled with copied Ethereum contracts and emptied when incentives stopped. Three things no L2 can offer. Keep your Ethereum deployment.

    -
  1. Proofs at the cost of power. A contract requests a proof of any computation and the miners produce it. Their cards already run and are paid by emission, so a job only has to beat a few seconds of lottery income. Verification is folded into the chain's own proof; you ship no verifier. The price is a base fee that rises with the backlog, published at the phase 4 job market.
  2. +
  3. Proofs priced by the subsidy forgone. A contract requests a proof of any computation and the miners produce it. Their cards already run and are paid by emission, so a job has to beat the lottery income the card forgoes while it proves. That is the price a prover must charge, as a formula with network hash as the input: per shard, (card hash ÷ network hash) × 0.8 × 31.688 IGN × shard seconds, plus electricity, which is under a cent per billion cycles on every card. It falls as one over network hash: at the devnet's 1.16 GH/s a quote is 100 to 300x the published market rate; a card proving beside its miner is competitive near 100 GH/s (the Horizon economy lane, 6 October 2026, sections 3.1 and 4.1, approximate beyond the one card measured; ledger E20). Verification is folded into the chain's own proof; you ship no verifier. The job's base fee rises with the backlog, published at the phase 4 job market.
  4. Users who were not paid to arrive. Every miner is a funded wallet. Pools, payout contracts, hardware finance and hashrate forwards have customers before any consumer app does. Block rewards can pay straight to a contract.
  5. A share of fees, with the number stated. 20% of every priority fee goes to the contracts whose code ran, per call frame, to the payee registered at deployment. Libraries are paid at their code address. Factories pass their registration to what they deploy. At launch fee levels this is a property, not an income: a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year, with 1 gwei taken as a billionth of an IGN (the base unit is Open). It grows with traffic and nothing else.
@@ -448,7 +448,7 @@ body.all .pager{display:none} ShareGoes toWhy 80%The miner who wins the blockPays the hashrate that secures the chain - 20%The proving pool: shard provers and aggregatorsFor a standing prover population that does not have to hash. On the devnet today the coinbase's 20% output goes to an unspendable script tagged igneum-proving-pool-v0 and is burned there. Provers are paid from a separate escrow in the execution state, credited by rule with the same 20% of each blue block's subsidy and released per shard against valid proof records (Implemented, proving v0, since 5 October 2026). Open: the single coinbase payout that replaces the burn, and whether it reclaims the share burned so far + 20%The proving pool: shard provers and aggregatorsFor a standing prover population that does not have to hash. On the devnet today the coinbase's 20% output goes to an unspendable script tagged igneum-proving-pool-v0 and is burned there. Provers are paid from a separate escrow in the execution state, credited by rule with the same 20% of each blue block's subsidy and released per shard against valid proof records (Implemented, proving v0, since 5 October 2026). Caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a block producer could claim shard pay with a false proof (ledger P21; the in-consensus verifier is the 0.3.16 fix). Note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven segment's pool (0.3.16). Open: the single coinbase payout that replaces the burn, and whether it reclaims the share burned so far 0%Treasury, foundation, team or stakeThere is no coin-holder class in consensus and no tax on emission @@ -462,9 +462,9 @@ body.all .pager{display:none} 1. Emission, per blockIGN, new coins on the schedule above80% the block's miner, 20% the proving pool for the provers of that blockNoneNone. Implemented in consensus: the 80/20 coinbase on the devnet 2. Base fee, both gas dimensionsIGNNobodyThe base fee the chain sets per blockAll of it. Implemented on the devnet 3. Priority feeIGN80% the block's miner and provers; 20% the apps whose code ran, per call frameThe tip the sender setsThe share of any frame in an unregistered contract. Implemented on the devnet - 4. External job, at launchThe customer's currency, on the customer's chainThe miner who delivered, through a payout contract keyed by miner addressPriced in dollars per proof; the customer chain's own bond and slashing applyNone; Igneum cannot see the payment. Designed + 4. External job, at launchThe customer's currency, on the customer's chainThe miner who delivered, through a payout contract keyed by miner addressPriced in the customer's money per proof, at or above the subsidy the prover forgoes (a formula in network hash, under Building on Igneum, never a fixed number); the customer chain's own bond and slashing applyNone; Igneum cannot see the payment. Designed 5. External job, after the proof bridgeIGN, on Igneum90% the provers who deliveredThe job fee10%. Designed, phase two - 6. The official client's dev feeIGNThe project, as operator income, never the protocol1 block template in 100 requested with the dev address; off with one flagNone. Implemented, measured on a test network 4 October 2026 + 6. The official client's dev feeIGNThe project, as operator income, never the protocoldefault-on, switchable, 1 percent of the producer share: 1 block template in 100 requested with the dev address; off with one flagNone. Implemented, measured on a test network 4 October 2026

Sources: specification sections 2.5 and 5.1 to 5.4; the engineering log for the devnet receipts and the dev-fee count.

@@ -495,7 +495,7 @@ body.all .pager{display:none}

The size of that third stream today, in numbers: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block, 7,200 blocks a day; the tracker figure is a secondary source), against about USD 13,700 a day of Igneum's year-1 emission at USD 0.005 per IGN (31.688 IGN a block, 86,400 blocks a day; the price is an input, not a forecast). So external proving is a small second income at launch and the lottery pays the bills; for proving to become the main income the paid demand would have to grow about 1,000x in dollars (the Horizon lane analysis, 6 October 2026, section 3.11; ledger E19).

-

The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' marginal cost in the proving market is close to power, which is an edge over data-centre provers and nothing more. Which of the two in-chain streams pays more per GPU-second depends on the size of the fleet: on the devnet of 4 October 2026, three machines at 275 million hashes a second, a second of hashing paid about 4.9x a second of proving the pool share; at 10,000 cards the same arithmetic favours proving by about 930x. That is arithmetic on measured devnet rates, approximate, not a market measurement.

+

The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' electricity cost in the proving market is close to power. The price they must charge is another matter: the price a prover must charge is the subsidy it forgoes while it proves, which falls as one over network hash, so the edge over data-centre provers appears only once the network's hash is large (near 100 GH/s for a card proving beside its miner) and is nothing more. Which of the two in-chain streams pays more per GPU-second depends on the size of the fleet: on the devnet of 4 October 2026, three machines at 275 million hashes a second, a second of hashing paid about 4.9x a second of proving the pool share; at 10,000 cards the same arithmetic favours proving by about 930x. That is arithmetic on measured devnet rates, approximate, not a market measurement.

Hardware

The dataset starts at 2 GB and grows (the proposed schedule, fixed at the testnet genesis: 2 GB, doubling at years 4, 12 and 28, the average of half a gigabyte a year), so a 4 GB card mines for about four years and an 8 GB card for about twelve, approximate. Every NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server (eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026). NVIDIA and AMD both work, because the mining program is generated for the architecture both share and the proof system is hash-based. Apple's chips are GPUs with unified memory, so Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second, an Apple M5 Max beside an RTX 5090 on the live devnet, 4 October 2026. A Mac is a poor miner per dollar. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.

What a miner's hour looks like

@@ -541,7 +541,7 @@ body.all .pager{display:none}

Measured: engineering log, "miner performance: variant racing" (lever 1), "first hourly program swap on the live devnet" and "miner fault guards and the app watchdog" (lever 5), 4 October 2026; the 0.3.6 release plan, the miner-latency gate (lever 4), 5 October 2026; the efficiency-sweep plan, the RTX 5090 log of 4 October 2026 (lever 3). Levers 2 and 3 are shipped code with no fleet measurement yet.

The software's fee, not the protocol's

-

The protocol is fee-free: no dev fund, no fee to any team, foundation or fund. Ember takes a 1% software dev fee, the norm for GPU miners. One block template in 100 is requested with the dev address instead of yours, by a counter, never a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. A fee block still carries your vote key, so it still adds to your finality weight. Ember prints the fee and the address when it starts, shows it in Settings next to a switch, and --dev-fee 0 turns it off, as does DEV_FEE=0 in a HiveOS flight sheet. Any other client is welcome.

+

The protocol is fee-free: no dev fund, no fee to any team, foundation or fund. Ember takes a 1% software dev fee, the norm for GPU miners: default-on, switchable, 1 percent of the producer share (the 80% of emission that pays the block's miner; the proving pool is paid per record and carries none of it). One block template in 100 is requested with the dev address instead of yours, by a counter, never a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. A fee block still carries your vote key, so it still adds to your finality weight. Ember prints the fee and the address when it starts, shows it in Settings next to a switch, and --dev-fee 0 turns it off, as does DEV_FEE=0 in a HiveOS flight sheet. Any other client is welcome.

Measured: engineering log, "the software dev fee measured on a test network", 4 October 2026: 9 fee blocks in 785 from two fee-paying miners, 0 from the control at --dev-fee 0, the chain and the miners' counters equal.

What Ember does not claim