Merge site-truth-2026-10-06: the ledger's stated sentences, the bounty struck, draft (a) on the chip line, the prover tiers, the ledger page, the evidence page from its source

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-06 16:12:30 +00:00
commit a714e625a2
25 changed files with 2163 additions and 173 deletions

View file

@ -16,6 +16,19 @@ A proof-of-work chain mined on consumer GPUs, where the same cards prove every I
| A versioned interface | Jobs run against the `ProofSystem` trait, version 1 of which is SP1. A later version is a release with its own test-vector set and a three-month overlap, so your integration survives a prover swap | Design document, execution layer, section 5.6 |
| Verification you can run | A job proof is a single proof your contract verifies on your own chain; Igneum's own segment proofs recursively verify it, so no relayer or committee is in the path | Designed |
## Every payment route
One row per route, so operator income and protocol income never blur. Rows 1 to 5 are the protocol. Row 6 is the project's software, outside the protocol, and is never added to the other five. Rules: specification sections 2.5 and 5.1 to 5.4; the fuller version with the diagram is `docs/design/payment-routes.md`.
| Route | Currency | Recipient | Fee | Burn |
|---|---|---|---|---|
| 1. Emission, per block | IGN, new coins on the published schedule | 80% the block's miner, 20% the proving pool for the provers of that block | None | None. Implemented in consensus on the devnet |
| 2. Base fee, both gas dimensions | IGN | Nobody | The base fee the chain sets per block | All of it. Implemented on the devnet |
| 3. Priority fee | IGN | 80% the block's miner and provers; 20% the apps whose code ran, per call frame | The tip the sender sets | The share of any frame in an unregistered contract. Implemented on the devnet |
| 4. External job, at launch | Your currency, on your chain | The miner who delivered, through a payout contract keyed by miner address | Priced in dollars per proof; your chain's own bond and slashing apply | None; Igneum cannot see the payment. Designed |
| 5. External job, after the proof bridge | IGN, on Igneum | 90% the provers who delivered | The job fee | 10%. Designed, phase two |
| 6. The official client's dev fee | IGN | The project, as operator income, never the protocol | 1 block template in 100 requested with the dev address; off with one flag | None. Implemented, measured on a test network 4 October 2026 |
## What you must do
1. Integrate against the versioned prover interface: the guest program hash (`program_id`) your batches are proven under, the public-input layout, and the proof encoding for version 1.

View file

@ -17,7 +17,7 @@ Four rules for reading the table:
1. Nothing on this chain has been reproduced externally or reviewed independently. Every row's last column says "none yet". The repository is private until the public testnet (decision of 5 October 2026), so the first three labels are the ceiling today.
2. A status applies to the exact version in the row. An audit of one version never covers a newer one; when the version changes, the status falls back to "tested by the team" until the new version is reproduced or reviewed again.
3. "Tested by the team" on one machine is one machine. The rows say which. Discrete AMD, Intel and a 2019-class CPU core have not run anything.
4. The 12-node cloud network of 4 October 2026 (`infra/cloud-devnet`, Hetzner VMs in five locations) is the project's own. Rows that cite it are tested by the team, not reproduced externally.
4. The 12-node cloud network of 4 October 2026 (`infra/cloud-devnet`, cloud VMs in five locations) is the project's own. Rows that cite it are tested by the team, not reproduced externally.
Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`, version 0.2.0 since 4 October 2026 (generator version 2; 0.1.0 rows are marked). "Repo" commits are this repository's. "Fork" commits are `vendor/igneum-node` and its worktrees (`-v4`, `-diff`, `-exec`, `-harness`, `-fin-fixes`), which are not in this repository's history; the row names the fork commit or branch as the bench log does. The live devnet is devnet v4 (genesis 10:05 BST, 4 October 2026, branch `devnet-v4`). The spec is `docs/spec/` version 0.1.
@ -41,7 +41,7 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`
| 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13; fixes `F-exec-A`, `F-exec-B` (spec 7.5) | `tools/evm-smoke/smoke.mjs`: deploy via viem, `increment`, `hashLoop`, `eth_estimateGas`, `eth_getLogs`; `tools/exec-attacks` scenarios 1 and 3; bench-log "execution layer attack fixes" | Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The `Prover` precompile, proof records and the shard planner are not in the node | none yet |
| 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | implemented | repo `d7e1f89` (GPU proof), `e01a3cc`, `292e800`, `eedd136` (`proving/igneum-prove`: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6 | `proving/windows-wsl2` (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; `igneum-prove-host --mode block` on `proving/fixtures/`; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards" | First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture `block-78-increment` (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in `docs/benchmarks/proving-e2e.md`. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Mac in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind `proving_v1_activation_daa` (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one | none yet |
| 16 | A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves) | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target), 7.6 (`S_p` provisional, 7,500,000 pgas = `B_p` / 4) | `PROVE-SHARD.bat` on the RTX 5090 (pending); the end-to-end standard in `docs/benchmarks/proving-e2e.md`; bench-log "proving: devnet v4 shards" | Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional `S_p` is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card | none yet |
| 17 | The chip resistance target: a chip gains under 2x over a GPU | Homepage hero and litepaper abstract ("a custom chip gains under 2x, and the model and the bounty are public"), litepaper "What Igneum does not claim" | tested by the team (the model), designed (the target) | program class v3 (Counter ASIC 2.0, 5 October 2026): branches ca2-v3 d233fa1 and after, ca2-mixer 1ab8b21, ca2-era 78c0ee4; `docs/analysis/chip-model-v3.md`, `docs/analysis/sram-mirror.md`, `docs/analysis/scratch-soundness.md` | The m16 recompute model re-run on the measured v3 rates and verifier times; the on-die-cache chip row | The on-die-cache recompute chip against the RTX 5090's measured 136.1 MH/s: class v2 2.4x; class v3 (mixer x8) 0.31x bare, 0.92x with a 3x fixed-function allowance (approximate), 0.76x at equal silicon; margin 8% on the allowance, 9% on the budget. 5 October 2026, M5 Max, RTX 5090, RX 9070 XT. The 2x target is a target: no chip has been built; the bounty stands (O-1.17) | none yet |
| 17 | The chip resistance claim: the strongest recompute chip under 1x per chip against an RTX 5090; the stored-dataset chip 1.2x per chip and 5x to 9x per joule in the model (2.1x to 4.8x by the Ethash precedent); the latency-shadow lever, measured and in its gates, brings it to about 2x | Homepage hero and litepaper abstract (draft (a) of `docs/plans/counter-asic-3-status.md` section 6, chosen 6 October 2026), litepaper "What Igneum does not claim" | tested by the team (the model), designed (the target) | program class v3 (Counter ASIC 2.0, 5 October 2026): branches ca2-v3 d233fa1 and after, ca2-mixer 1ab8b21, ca2-era 78c0ee4; `docs/analysis/chip-model-v3.md`, `docs/analysis/sram-mirror.md`, `docs/analysis/scratch-soundness.md` | The m16 recompute model re-run on the measured v3 rates and verifier times; the on-die-cache chip row | The on-die-cache recompute chip against the RTX 5090's measured 136.1 MH/s: class v2 2.4x; class v3 (mixer x8) 0.31x bare, 0.92x with a 3x fixed-function allowance (approximate), 0.76x at equal silicon; margin 8% on the allowance, 9% on the budget. 5 October 2026, M5 Max, RTX 5090, RX 9070 XT. The 2x target is a target: no chip has been built; the bounty stands (O-1.17) | none yet |
| 18 | The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache | Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page | tested by the team | readwidth e752fc7 (`docs/plans/read-width.md`), ca2-era 78c0ee4, ca2-cache 2de19e5 (`docs/plans/hot-table.md`) | The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load | Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026 | none yet |
| 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors | Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page | tested by the team | ca2-mixer 1ab8b21 (`tests/mixer.rs`, `tests/scratch.rs`), ca2-era 78c0ee4, ca2-soundness a465881 (`docs/analysis/scratch-soundness.md`), `igneum-pow/tests/packs.rs` | The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card | Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing) | none yet |
| 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo `6ac80a3`; fork "igneum-node devnet v0"; `consensus/core/src/igneum.rs`, `coinbase.rs` | `cargo test -p kaspa-consensus-core igneum` (8 pass: subsidy table, ramp, split, cap) and `cargo test -p kaspa-consensus coinbase` (8 pass); `igneum-miner inspect 40`; bench-log "igneum-node devnet v0" | Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the `igneum-proving-pool-v0` output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened | none yet |
@ -53,8 +53,9 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`
| 26 | A phone or browser verifies the chain from a locked checkpoint, at about 3.44 MB per day in checkpoint mode | Homepage "Browser checks Igneum" card; litepaper Building ("Light clients"), firsts row 6 | designed | spec 10 (10.5 bytes per day: 3.44 MB at 1,000 voters, 6.68 MB at 10,000, derived, approximate); repo `f874f80` for the browser card; `site/api/checkpoint.mjs` | None for the byte figure; `site/verify/` for the card against `/api/checkpoint`. BLS verification on a phone and in WebAssembly is O-10.3; the full-header mode on a phone is O-10.4 | Since 12:03 BST on 4 October 2026 the homepage card verifies the live devnet's own certificates in the tab (index 522 with 27 voters at 13:42 UTC), BLS aggregate against the voter list the node serves, light client v0; before that it verified the 3 October test network's. The byte figure is arithmetic on designed sizes (header 400 bytes, proof 400 bytes), measured nowhere; the execution proof the card would also check is not on the chain (row 15) | none yet |
| 27 | The node survives malformed input, floods, withholding, partitions and eclipses | Litepaper Speed ("GHOSTDAG, the BlockDAG consensus proven on Kaspa"); spec 2 | tested by the team | repo `394030c`, `8dae48b`, `6b5bd92`; fork worktree `vendor/igneum-node-harness` and `devnet-v4`; `tools/harness/`; `infra/cloud-devnet/experiments/partition.sh` | `tools/harness/` against a private `igneumd` test network; the merged node's harness scenarios 2 and 5; the cloud network's 10-minute partition of Singapore (`results/2026-10-04/partition-sin-20261004-110906/partition.md`); bench-log "consensus attack harness", "devnet-v4 integration" | 3 October 2026, Apple M5 Max: 63 malformed cases, node up on every one; withholding at 10% to 45% within 2 sigma of share; partitions of 120 s to 3,700 s healed to one chain in 10 s; eclipse victims rejoined in 10 s; 50x floods left template p95 under 4 ms; one FAIL, a 45% withholder releasing every 20 blocks took 50.7% of blues (bound 47.4%). Merged node, 4 October 2026: 63 cases, node up, 0 cache builds; the 10 s timestamp floor and future bound exact. Cloud network, 4 October 2026: 12 nodes in five locations on their own chain, Singapore cut off by iptables for 10 minutes; the two minority nodes adopted the majority chain 10 and 14 s after the heal with reorgs of 445 and 516 blocks, the majority's deepest reorg was 2 blocks, 0 conflicting locks (none were possible: the weight window stood at DAA 3,030 of 7,200). CPU miners only; the finality rules under partition are row 10 | none yet |
| 28 | Headers are validated cheaply before the lottery engine runs, so forged timestamps cannot force 256 MiB cache builds | Spec 2.4; ledger M15 | tested by the team | repo `0953ec7`, `8dae48b`; fork worktree `vendor/igneum-node-r3` branch `r3-fixes` at `5166ee26`, merged into `devnet-v4` | `measure_m15_attack_before_and_after` (ignored test, release, `--features igneum-pow`); kaspa-pow 8, header_processor 1, p2p `pow_guard` 2 tests; harness scenario 5 on the merged node | 50 forged headers: before, 50 cold builds in 10,595 ms and the live day evicted; after, 0 builds, all 50 rejected in 14 ms, 3 October 2026, Apple M5 Max under load 60 to 110. Merged node, 4 October 2026: 63 harness cases with 0 cache builds (the node log shows one build, the honest day) and the M15 p2p cases disconnected by the strike guard; the live devnet v4 runs it. Measured through the validate path with `skip_proof_of_work`, not the daemon RPC | none yet |
| 29 | Blocks reach every node well inside GHOSTDAG's delay bound across continents | Litepaper Speed (GHOSTDAG at one block a second); spec 03 C1 (lock latency); `infra/cloud-devnet/README.md` | tested by the team | repo `6b5bd92`; `infra/cloud-devnet/experiments/latency.sh`, `analyze.py`; the Linux cross-build `infra/cross/build-linux.sh` | 12 `igneumd` nodes on Hetzner VMs in Helsinki, Falkenstein, Ashburn, Hillsboro and Singapore (own chain `igneum-devnet-20`, one CPU trickle miner each), a ping matrix, then 10 minutes of per-node arrival logs joined on block hash; `results/2026-10-04/latency/propagation.md` and `rtt-by-region.md` | 644 blocks in the window, 642 seen by at least 80% of nodes; arrival at a node minus the first arrival anywhere: p50 343 ms, p90 497 ms, p99 666 ms, max 2,313 ms; by region p50 239 ms (Falkenstein) to 413 ms (Singapore), p90 455 to 632 ms; inter-region RTT 35 ms (Helsinki to Falkenstein) to 289 ms (Ashburn to Singapore); first arrival minus header time median 490 ms. 4 October 2026. The network is the project's own: 12 nodes not 20 (a new account's limits), CPU hash rate only, clocks by chrony, one evening of data; the 5 s bound behind GHOSTDAG k is a design parameter this run did not challenge | none yet |
| 29 | Blocks reach every node well inside GHOSTDAG's delay bound across continents | Litepaper Speed (GHOSTDAG at one block a second); spec 03 C1 (lock latency); `infra/cloud-devnet/README.md` | tested by the team | repo `6b5bd92`; `infra/cloud-devnet/experiments/latency.sh`, `analyze.py`; the Linux cross-build `infra/cross/build-linux.sh` | 12 `igneumd` nodes on cloud VMs in Helsinki, Falkenstein, Ashburn, Hillsboro and Singapore (own chain `igneum-devnet-20`, one CPU trickle miner each), a ping matrix, then 10 minutes of per-node arrival logs joined on block hash; `results/2026-10-04/latency/propagation.md` and `rtt-by-region.md` | 644 blocks in the window, 642 seen by at least 80% of nodes; arrival at a node minus the first arrival anywhere: p50 343 ms, p90 497 ms, p99 666 ms, max 2,313 ms; by region p50 239 ms (Falkenstein) to 413 ms (Singapore), p90 455 to 632 ms; inter-region RTT 35 ms (Helsinki to Falkenstein) to 289 ms (Ashburn to Singapore); first arrival minus header time median 490 ms. 4 October 2026. The network is the project's own: 12 nodes not 20 (a new account's limits), CPU hash rate only, clocks by chrony, one evening of data; the 5 s bound behind GHOSTDAG k is a design parameter this run did not challenge | none yet |
| 30 | One click: install, press start, the card mines; the app looks after its node | Homepage Mine section ("One click: install, press start"); litepaper "One click, for everyone else"; journey phase 5 | tested by the team | repo `3bb50d6`, `2c4b30f`, `6461540` (package 0.3.0: prebuilt NVRTC CUDA worker and generic OpenCL worker, driver only), `a1a33cb`, `7c794df`, `0d4498e`, `6c083db` (Igneum Miner 0.3.0), `78903cd` (0.3.1, over-the-air updates) | `Igneum-Miner-Setup-0.3.0.exe` (runner-built, unsigned) on a Windows PC with an RTX 5090 and no toolchain; `proto-cuda/nvrtc/emu/serve-check.sh` on the Mac; `proto-cuda/windows-app/TEST.md`; bench-log "one-click Windows workers", "first machine on the Igneum Miner app", "a node 60 s behind the clock is silently dead", "the gfx1036 worker fault" | Four machines by 15:45 BST on 4 October 2026: PC 2, then PC 1 (RTX 5090 at 110 MH/s under the 80% power cap), the project's Apple M5 Max (25 MH/s) and the outside Apple silicon laptop (row 29), all on Igneum Miner 0.3.1. The NVRTC worker compiled the pack on the card with no toolchain installed and mined at 124.2 MH/s, equal to the nvcc-built worker, 0 rejected, CPU re-check clean; inside the app 117 to 119 MH/s with 34 accepted blocks in the first minute, the integrated AMD chip at 3.3 MH/s beside it (row 9). Two defects found by the install, both fixed the same hour: a clock 62 s slow after a power cut made the node reject every relayed block for 12 minutes with no visible reason (the app now reads the skew from the node's warnings, the block timestamps over the EVM RPC and an HTTPS Date header, warns over 5 s and blocks Start over 10 s, with a one-click clock sync; checked on the Mac with a fake 60 s skew; a one-line node warning is filed), and the node card said "syncing" while the miner was already accepted. The Mac could only emulate the NVIDIA path (17 of 17 sampled hashes) and the AMD path on Apple OpenCL (15 of 15). Over-the-air updates were dry-run on a private devnet (0.3.0 to 0.3.1 and back), not on a user's machine. The installer is unsigned (SmartScreen "run anyway"). Second machine, the same afternoon: a friend of the project installed Igneum Miner 0.3.1 from the DMG on an Apple silicon laptop with no toolchain and no instructions beyond five steps; the node synced from the seed, the Metal worker reported ready, 33 accepted blocks and 0 rejected in 7 minutes at 21.0 MH/s average, CPU re-check OK on every share, uploads arriving every minute under its per-install id. That laptop is not the project's hardware, but the result is observed through the project's own log intake and reported by the project, so it stays tested by the team until an outsider publishes a run of their own. The devnet's other GPU machines (PC 1 and the Mac) run the same workers through the launcher, not the app | none yet |
| 31 | Card lifetime: a 4 GB card mines about four years and an 8 GB card about twelve, under the dataset's step schedule (2 GB at genesis, doubling at years 4, 12, 28, 60) with the cache freed after the daily build | Litepaper Hardware and vs RandomX ("Dataset" row); homepage Mine card and "Memory" row | designed | `docs/analysis/card-lifetime-2026-10-05.md` (branch card-lifetime 1fecfe2); spec 1.13.3 option (b) recommended to the owner 5 October 2026 (`docs/plans/counter-asic-2-rollout.md` 6c) | The per-tier working-set arithmetic of that document (GTX 1650, RTX 3050, RTX 3060, RTX 4090 tiers) against the step schedule | A design claim: under the continuous mapping (a) a 4 GB card is out within 1 to 1.5 years and an 8 GB card at 6 to 7.5 years, so the sentence is true only under the step schedule (b), which the spec has not yet fixed (O-1.13) | none yet |
## Count by status
@ -66,7 +67,7 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`
| reproduced externally | 0 |
| reviewed independently | 0 |
30 rows. The rendered page is `site/evidence.html`, kept in step by hand with this file; the bench page is generated, this one is not, because its text is judgement, not a log.
31 rows. The rendered page is `site/evidence.html`, generated from this file by `site/build.mjs` (since 6 October 2026); the text is judgement, so this file is edited by hand and the page follows.
## What moved on 4 October 2026
@ -87,7 +88,6 @@ Versions in the table: `igneum-pow` is the Rust crate at `igneum-pow/Cargo.toml`
|---|---|---|---|
| 15 | implemented | implemented, with a live result | the first non-empty shard (block 72704, 29 transfers) proven, verified and paid on the devnet; not every block is proven yet |
| 21 | designed | tested by the team | 388 shards paid from the pool on the live devnet, the rule in `proving.rs`, the numbers in the bench log |
| 22 | Card lifetime: a 4 GB card mines about four years and an 8 GB card about twelve, under the dataset's step schedule (2 GB at genesis, doubling at years 4, 12, 28, 60) with the cache freed after the daily build | Litepaper Hardware and vs RandomX ("Dataset" row); homepage Mine card and "Memory" row | designed | `docs/analysis/card-lifetime-2026-10-05.md` (branch card-lifetime 1fecfe2); spec 1.13.3 option (b) recommended to the project lead 5 October 2026 (`docs/plans/counter-asic-2-rollout.md` 6c) | The per-tier working-set arithmetic of that document (GTX 1650, RTX 3050, RTX 3060, RTX 4090 tiers) against the step schedule | A design claim: under the continuous mapping (a) a 4 GB card is out within 1 to 1.5 years and an 8 GB card at 6 to 7.5 years, so the sentence is true only under the step schedule (b), which the spec has not yet fixed (O-1.13) | none yet |
## What would move a row

View file

@ -312,6 +312,29 @@ Added by `docs/review/ledger-sweep-2026-10-05.md`, which holds what ran, what di
| 126 | E12 | The devnet half of O-5.9 (profit-only prover clients, `f_p` and `B_p` paths) | Phase 4 devnet run as the ledger entry states (4 h) | execution engineer | before testnet | no |
| 127 | M25 | Confirmed 5 October 2026 (sweep batch 3): a miner started with a different `IGNEUM_POW_DAY_MS` builds its cache for another day and every block is rejected as `BlockInvalid` / `block has invalid proof-of-work`, with no line naming the day (0 of 4 accepted against 7 of 7 for the control) | The day length (or the day index) in the template beside `pow_epoch`, the miner takes it from there and ignores the environment; the node's PoW rejection names the engine's day and the header's day (1.5 h) | miner lead, consensus engineer | before testnet | no |
### 2.7 Close round 1 (5 October 2026, night)
Appended by the public-text closer (worktree `igneum-wt-ledger-text`, branch `ledger-text`, group A of `docs/plans/ledger-close-plan.md`). Every sentence named here was grepped in the public text before the ledger row moved. Rows name the earlier row they touch; nothing above is rewritten.
| Row touched | Ledger | What changed (5 October 2026, night) | Who next | When |
|---|---|---|---|---|
| 17, 48, 53, 56, 15 | M2, M4, M7, M9, M10 | Verified and moved to "Conceded, stated" (M10: "Answered with evidence, stated"). M10's overclaim 14 was still live at 18:20 UTC and is applied now: "bound by random memory access", 95 GB/s of useful loads against 1,638 GB/s sequential, RTX 5090 | none | done |
| 19 | M13 | "a fifth" confirmed in For miners, Hardware (26.7 against 123 MH/s, 4 October 2026); moved | none | done |
| 10, 11 | F5, F10 | Verified and moved | none | done |
| 57, 21, 22, 24, 25, 26 | P1, P3, P4, P6, P7, P10 | Verified and moved. P3: overclaim 25 applied ("Wrapped for light clients ... phase two measurement") with the certificate-half numbers of bench-log round 6 (139 to 155 ms cold, 58 to 68 ms warm, laptop core, no phone); the wrapper stays Open for phase two | measurement (the wrapper) | before public repo |
| 8, 27 | E5, E6 | E5 verified and moved. E6: one sentence in Security after the subsidy, "The schedule is a bet, not a measurement", Kaspa's reduction marked approximate; moved | none | done |
| 28, 29, 9, 30, 32 | G1, G2, G3, G4, G6 | Verified and moved. G3: the entry's first Status line is now the Decided line (no team page; "The team is pseudonymous and there is no team page" in the litepaper), the older line kept prefixed "Was:" | none | done |
| 14, 12, 13, 34, 49 | C2, C3, C5, C6, C8, C10, C11 | Verified and moved | none | done |
| (C13, M18, L8) | C13, M18, L8 | C13: "they say nothing about the price of a chip with the 256 MB cache on its die" in What Igneum does not claim. M18 verified. L8: "whether it is issued is Circle's decision" in Questions builders ask; Canto and Blast absent. All moved | none | done |
| 6 | L2 (text half) | "so the people who show up early get the most" removed from Supply; schedule fact only. Counsel half unchanged, decision owner the project lead | the project lead, counsel | before public repo |
| 110 | L9 | "Devnet: coins have no value and the chain may be reset." beside every download control on index, miner and wallet; the homepage tiles read "of emission to miners and provers; the protocol carries no fee" and "0% anyone else in the protocol". Not done: the same line on `/live` (outside this round's files) | Claude (live page) | now |
| 111 | M29 | The litepaper's app paragraph rewritten to Ember 0.3.9 from the shipped UI; earnings, currency, game pause and the hardware wallet moved to a roadmap sentence; nothing from an unmerged branch | none | done |
| 109 | E16 (text half) | The 20% row and the homepage bar now say the coinbase's 20% output is burned under `igneum-proving-pool-v0` and provers are paid from the execution-state escrow credited with the same 20%; the single coinbase payout stays Open (code half, group D) | consensus engineer (payout) | before testnet |
| 115 | E17 (text half) | "a million 100,000-gas calls a day" with the base unit marked Open; the fleet-size dependence sentence (4.9x today, 930x at 10,000 cards, approximate). Draw lines still owed | measurement (draw lines) | when convenient |
| 94 | E13 | The six-row route table in the litepaper Economics ("Every payment route") and in the customer brief; source `docs/design/payment-routes.md`; moved to "Conceded, stated". That file's section 4 states are of 3 October and now lag the litepaper | Claude (refresh payment-routes.md section 4) | when convenient |
| 1, 2, 39, 3, 4 | X1, X2, X3, X7, X8 | Verified and moved. X3: "Live rows arrive with the public testnet, August 2027" under the proofs feed (overclaim 61); the old sentence was already gone. X7 closes on the ledger's submission line (hello@igneum.network, spec issues) | none | done |
| 36, 5 | X9, X10, D2 | Verified and moved; D2's sentence now reads "100,000-gas calls" (E17) | none | done |
## 4. What the 3 October decisions close or change
Closed:
@ -362,3 +385,4 @@ Nothing below is optional. The history, not just the working tree, carries the n
9. Put the GitHub links back on HP and the /bench page (row 1) on the day the repository opens, at the public testnet.
What is already clean: `docs/bench-log.md` and the /bench page name machines, not people (commit 1769eda); the live site returns 404 for everything under `docs/` and 307 for `/ledger`; `site/.env.local`, `site/.vercel/` and `vendor/` are ignored; no tracked file carries a home-directory path; no connection string or token appears anywhere in the history.
| 128 | P23 | The EVM pool has `on_chain_block` and no reorg hook, so a transaction unwound by a selected-chain reorg leaves the node until its sender resends (found by the P17 conformance run, 6 October 2026) | A reorg hook: unwound transactions handed back to the pool as pending with the usual checks; unit test; the conformance driver's `reorged out` case ends in `executed` without a resend (2 h) | execution engineer (round 3 `ledger-rebase` carries it) | before a public RPC | no |

File diff suppressed because it is too large Load diff

View file

@ -4,7 +4,7 @@ the project lead, 5 October 2026 (night): "not an information overload". Four le
## Level 1: one sentence (site hero, litepaper abstract)
Built for graphics cards. A custom chip gains under 2x, and the model is public. (The bounty is named only once it is escrowed: docs/plans/funding.md rule 3; D11 for the project lead.)
Built for graphics cards. A custom chip gains under 2x, and the model is public. (the project lead's decision of 6 October 2026, 17:35 UTC, ledger M1: no device bounty; the claim is backed by the paid independent cryptanalysis (CA 3.0 item 3, four paid reviews) and the public benchmark with M22's metrics; an optional USD 50,000 cryptanalysis prize may follow later, escrowed before it is named.)
## Level 2: one site card, one short litepaper section
@ -16,7 +16,7 @@ Three ideas, no layer names, no widths, no SRAM.
**Miners hold the switch.** Spare defences are written into the rules, switched off. A 90% miner signal turns one on. No fork.
A custom chip gains under 2x. Model published; a bounty follows the external review. [link: the numbers page]
A custom chip gains under 2x. Model published; tested by paid independent cryptanalysis and the public benchmark. [link: the numbers page]
Litepaper only, a fourth paragraph: No hash has stayed free of chips forever. Igneum does not claim to. It claims the gain is small, the response takes a week, and both are measured.
@ -26,7 +26,7 @@ Site card placement: the Mine section of `site/index.html` beside "no chip can b
Headline of the chip model (5 October 2026, night): the strongest chip holds the whole 256 MiB cache on-die (about 128 mm^2 and $46 of silicon at N5 by shipped cache-die density, approximate) and computes dataset items on the fly; its gain over the RTX 5090 is 2.4x as the parameters stand, and no write-scratch share within an 8 GB card's budget changes that. The lever that does is the dataset item's mixer cost (x4: 1.8x with a 3x fixed-function factor, verifier 1.6 to 4.8 ms per warp). Decided 5 October 2026 (delegated): the mixer x4 and the cache growth rule enter class v3, so the headline row is the on-die-cache chip against v3 with everything combined. [owed: the combined row from docs/analysis/chip-model-v3.md; if it reads 1.8x, the claim is "under 2x" with the margin stated as thin, and the next levers are named: the mixer x8 and the hot table.]
Per card, the bench table: the v2 class and the v3 class, hash rate, bytes per hash, the latency-bound share (rate over the card's random-read ceiling per load), the CPU verifier per warp, with machine, date and command. The chip model before and after Counter ASIC 2.0 (the m16 model's gain arithmetic at the v2 class and at the v3 class, with the SRAM a mirror needs, cited or approximate as the analysis says). The bounty terms (spec O-1.17: the leaderboard by card model, the standing bounty for any chip design beating a GPU by more than 2x, January 2027). Here the layers are named next to their numbers: read width, per-program mix, scratch, era layout, working set, hot table, cache schedule, the reserved integer-matrix family.
Per card, the bench table: the v2 class and the v3 class, hash rate, bytes per hash, the latency-bound share (rate over the card's random-read ceiling per load), the CPU verifier per warp, with machine, date and command. The chip model before and after Counter ASIC 2.0 (the m16 model's gain arithmetic at the v2 class and at the v3 class, with the SRAM a mirror needs, cited or approximate as the analysis says). The benchmark terms (spec O-1.17: the leaderboard by card model and the paid independent cryptanalysis's published findings, January 2027; no device bounty by the project lead's decision of 6 October 2026). Here the layers are named next to their numbers: read width, per-program mix, scratch, era layout, working set, hot table, cache schedule, the reserved integer-matrix family.
| Card | v2 MH/s | v3 MH/s (era packs, six eras) | Bytes per hash | Latency-bound share | Verifier ms per warp (v2 / v3, one loaded M5 Max core) | Daily 1 GiB build (v2 / v3) |
|---|---|---|---|---|---|---|

View file

@ -9,7 +9,7 @@ The third set of chip-resistance layers, from the ASIC-history agent's audit of
| 1 | The partial-store chip and the time-memory curve: price a chip that holds a fraction f of the dataset (f = 0.25, 0.5, 1) on HBM3 or GDDR7 with 4-byte access granularity and recomputes the rest, scored in energy per hash | the only chip class that beat a memory-bound GPU hash (Ethash: 2.1x Linzhi 2020, 2.9x E9 2022, 4.8x per joule Jasminer X4 2021) did it with custom memory controllers and on-package memory, not an on-die dataset; chip-model-v3.md prices only f = 0 | `docs/analysis/chip-model-v3.md`, O-1.6, MEMHARD.md section 3 item 2 (the curve never drawn) | analysis, before the public testnet's vectors freeze; the first item |
| 2 | A random item-derivation program per day in place of the fixed-shape mixer (RandomX's SuperscalarHash idea) | the fixed mixer shape IS the 3x fixed-function allowance that turns x8's 0.31x into 0.92x; removing it is worth more than x16 (0.46x with the factor) | a reserve family now; genesis if the per-day compiled derivation verifies under the 10 ms gate (unmeasured); risks: cryptanalysis of random ARX, weak draws, bit-exact compilation on three vendors; the daily build about doubles (23 to 77 ms, approximate) | design and the verifier measurement |
| 3 | External cryptanalysis of the mixer M_r, the chained cache and the acceptance rule, with the x8 shape as the target | MTP fell from 2 GB to under 1 MB before launch (Dinur and Nadler 2017), Catena's proofs were flawed, Argon2i's parameters were attackable; RandomX bought four audits for about $141,000 before launch; x8 multiplies the mixer's weight in the chip model, so a structural shortcut is worth 8x more | ledger M7, raised to a genesis gate | commission before genesis |
| 4 | The clock and the detector: (a) a share-pattern detector on the observer (per-program hash-rate spread, nonce-group patterns, per-card-model rate bands; alert when a population behaves like one fixed design: how MoneroCrusher found Monero's secret chips at 85% of the hashrate, February 2019); (b) the bounty's trigger as daily issuance in dollars, not a date (compute-bound hashes got chips at $20K to $30K a day: Radiant, Kadena, Handshake; Vorick's 2018 rule about $55K a day) | not a layer: the response time | the observer (`tools/observer`), D11 (the bounty is unfunded) | before the public testnet |
| 4 | The clock and the detector: (a) a share-pattern detector on the observer (per-program hash-rate spread, nonce-group patterns, per-card-model rate bands; alert when a population behaves like one fixed design: how MoneroCrusher found Monero's secret chips at 85% of the hashrate, February 2019); (b) the audit-and-benchmark trigger as daily issuance in dollars, not a date (no device bounty: the project lead, 6 October 2026, 17:35 UTC, ledger M1; the trigger brings forward the paid cryptanalysis and the benchmark's next round) (compute-bound hashes got chips at $20K to $30K a day: Radiant, Kadena, Handshake; Vorick's 2018 rule about $55K a day) | not a layer: the response time | the observer (`tools/observer`), D11 (no device bounty; the trigger brings forward the paid cryptanalysis and the benchmark round) | before the public testnet |
| 5 | Rank layer 9 (the epoch length) above layer 7 and measure the FPGA lane: a soft-overlay FPGA with HBM (reads in flight per watt against the 5090's 17.5 G/s) added to the compile-ahead measurement | FPGAs were the first adversary of Lyra2REv2 (2018) and X16R (1.3x, September 2019) and came back within weeks of X16Rv2; Xelis forked for FPGA resistance (July 2024); a per-hour compiled program is a bitstream target | `docs/plans/epoch-length.md` | measurement before the public testnet |
| 6 | Order the reserve by chip-unfriendliness: the 32-bit datapath families first (byte permute, bit-field extract, variable shifts, popcount, select, the second shuffle), mm8 last | int8 matrix blocks are licensable IP at every node; Apple pays 1.6x to 4.7x per emulated dot4; Least Authority's ProgPoW suggestion 5 was "watch ML hardware" | spec 1.13.2 | a decision for the project lead with the 3.0 measurements |
| 7 | A vendor-share metric (hashrate by vendor) published with the benchmark | the 7.5x AMD gap is a softer form of the capture the history records (Kaspa's GPU share went to nothing within months of KS0) | the numbers page, the observer | with the public benchmark |
@ -18,7 +18,7 @@ Placed nowhere, with the reasons in the history document's section 4.3: per-hash
## Decisions for the project lead raised by the history
Add the partial-store rows before the vectors freeze; name the random derivation as a reserve family and fund its verifier measurement; commission the mixer cryptanalysis; escrow the bounty on an issuance trigger and build the detector; rank the epoch-length reserve above mm8.
Add the partial-store rows before the vectors freeze; name the random derivation as a reserve family and fund its verifier measurement; commission the mixer cryptanalysis; put the paid cryptanalysis and the benchmark round on an issuance trigger and build the detector; rank the epoch-length reserve above mm8.
## The plan, in order

View file

@ -160,6 +160,7 @@ p{margin:0;color:var(--ink-2);max-width:52ch}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -233,6 +233,7 @@ main{padding-bottom:var(--sec)}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

File diff suppressed because one or more lines are too long

View file

@ -234,6 +234,7 @@ main{padding-bottom:var(--sec)}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -312,6 +312,42 @@ function stampDownloads(html, file, dl) {
const downloads = await loadDownloads();
built.push(`downloads (${downloads.source}: ${Object.keys(downloads.files || {}).join(', ') || 'none'})`);
// the evidence page (/evidence): the claims table, the counts and the date are rendered from docs/evidence.md (6 October 2026);
// the page's prose stays in site/evidence.html, the rows are judgement edited in the markdown and follow from there.
function renderEvidence(html) {
const mdp = join(docs, 'evidence.md');
if (!existsSync(mdp)) return html;
const src = readFileSync(mdp, 'utf8');
const start = src.indexOf('\n| # | Claim |'); const end = src.indexOf('\n## Count by status');
if (start < 0 || end < 0) throw new Error('evidence.md: claims table not found');
const rows = src.slice(start, end).split('\n').filter(l => /^\| \d+ \|/.test(l));
const LABELS = ['designed', 'implemented', 'tested by the team', 'reproduced externally', 'reviewed independently'];
const inl = t => esc(t.trim()).replace(/`([^`]+)`/g, (m, c) => `<code>${c}</code>`);
const cells = l => l.replace(/^\| /, '').replace(/ \|$/, '').split(' | ');
const counts = Object.fromEntries(LABELS.map(k => [k, 0]));
const tr = rows.map(l => {
const c = cells(l); if (c.length !== 8) throw new Error(`evidence.md: row ${c[0]} has ${c.length} cells`);
const [n, claim, where, status, ver, test, result, iv] = c;
const idx = LABELS.findIndex(k => status.toLowerCase().includes(k)); if (idx < 0) throw new Error(`evidence.md: row ${n} status "${status}"`);
counts[LABELS[idx]]++;
return `<tr data-status="${LABELS[idx]}"><td class="n">${n}</td><td class="claim">${inl(claim)}<div class="where">${inl(where)}</div></td><td><span class="st st-${idx}">${inl(status)}</span></td><td class="mono">${inl(ver)}</td><td>${inl(test)}</td><td>${inl(result)}</td><td class="iv">${inl(iv)}</td></tr>`;
}).join('\n');
// the same scrub as /bench: local-time stamps to UTC and the private-string check (the build fails on any hit)
const trs = scrubBench(tr);
html = html.replace(/(<table id="claims">[\s\S]*?<tbody>)[\s\S]*?(<\/tbody>)/, (m, a, b) => `${a}\n${trs}\n${b}`);
for (const k of LABELS) {
html = html.replace(new RegExp(`(<div class="label"><div class="k">${k}</div><div class="v">)\\d+(</div>)`), `$1${counts[k]}$2`);
html = html.replace(new RegExp(`(data-filter="${k}"><b>)\\d+(</b>)`), `$1${counts[k]}$2`);
}
html = html.replace(/(data-filter=""><b>)\d+(<\/b>)/, `$1${rows.length}$2`);
const d = new Date(); const MON = ['Jan','Feb','Mar','Apr','May','Jun','Jul','Aug','Sep','Oct','Nov','Dec'];
const day = `${d.getUTCDate()} ${MON[d.getUTCMonth()]} ${d.getUTCFullYear()}`;
const dayLong = `${d.getUTCDate()} ${['January','February','March','April','May','June','July','August','September','October','November','December'][d.getUTCMonth()]} ${d.getUTCFullYear()}`;
html = html.replace(/<div class="eyebrow">\d+ claims · 5 labels · [^<]*<\/div>/, `<div class="eyebrow">${rows.length} claims · 5 labels · ${day}</div>`);
html = html.replace(/<p class="asof">Statuses are honest as of [^<]*<\/p>/, `<p class="asof">Statuses are honest as of ${dayLong}, the day this page was generated from docs/evidence.md, and change only through that file.</p>`);
return html;
}
const PAGES = [['index.html', ''], ['litepaper.html', 'litepaper'], ['live.html', 'live'], ['evidence.html', 'evidence'], ['miner.html', 'miner'], ['wallet.html', 'wallet'], ['metamask.html', ''], ['faucet.html', ''], ['404.html', ''],
// the DAG explorer (5 Oct 2026): /explorer, /block/<hash> and /address/<addr> (vercel.json rewrites the last two)
['explorer.html', 'live'], ['block.html', 'live'], ['address.html', 'live']];
@ -324,6 +360,7 @@ for (const [file, active] of PAGES) {
html = inject(html, 'footer', FOOT, file);
html = stampProduct(html, file);
html = stampDownloads(html, file, downloads);
if (file === 'evidence.html') html = renderEvidence(html);
if (file === 'index.html') html = inject(html, 'journey', `<script type="application/json" id="journey-data">${JSON.stringify(journey).replace(/</g, '\\u003c')}</script>`, file);
writeFileSync(p, html);
built.push(file);

View file

@ -175,52 +175,53 @@ code{font-family:var(--f-mono);font-size:.92em;background:var(--obsidian);paddin
<!-- nav:end -->
<main id="main" class="wrap">
<div class="head">
<div class="eyebrow">30 claims · 5 labels · 4 Oct 2026</div>
<div class="eyebrow">31 claims · 5 labels · 6 Oct 2026</div>
<h1>Evidence</h1>
</div>
<p class="note">Every claim the homepage and the litepaper make, one row each, with one of five labels: <b>designed</b> (a decision, no code), <b>implemented</b> (code with passing test vectors), <b>tested by the team</b> (measured by the project on a named machine, in the engineering log), <b>reproduced externally</b> (a third party ran the published command and got the published result) and <b>reviewed independently</b> (a named outside reviewer published a finding on that version). Nothing on this chain has been reproduced externally or reviewed independently; every row says so. A label belongs to the exact version in the row, and an audit of one version never covers a newer one. The 12-node cloud network of 4 October 2026 is the project's own, so its rows are tested by the team, not reproduced externally.</p>
<div class="labels">
<div class="label"><div class="k">designed</div><div class="v">6</div><p>A decision in the design document or the specification. No code, or a stub</p></div>
<div class="label"><div class="k">implemented</div><div class="v">3</div><p>Code in the repository with test vectors that pass. Not measured as the claim</p></div>
<div class="label"><div class="k">tested by the team</div><div class="v">21</div><p>Measured or exercised by the project on a named machine, with the command in the log</p></div>
<div class="label"><div class="k">tested by the team</div><div class="v">22</div><p>Measured or exercised by the project on a named machine, with the command in the log</p></div>
<div class="label"><div class="k">reproduced externally</div><div class="v">0</div><p>None yet. The repository is private until the public testnet</p></div>
<div class="label"><div class="k">reviewed independently</div><div class="v">0</div><p>None yet. What review would cost and who pays is in the funding plan</p></div>
</div>
<div class="chips" role="group" aria-label="Filter by status"><button type="button" class="chip on" aria-pressed="true" data-filter=""><b>30</b> all</button><button type="button" class="chip" aria-pressed="false" data-filter="designed"><b>6</b> designed</button><button type="button" class="chip" aria-pressed="false" data-filter="implemented"><b>3</b> implemented</button><button type="button" class="chip" aria-pressed="false" data-filter="tested by the team"><b>21</b> tested by the team</button><button type="button" class="chip" aria-pressed="false" data-filter="reproduced externally"><b>0</b> reproduced externally</button><button type="button" class="chip" aria-pressed="false" data-filter="reviewed independently"><b>0</b> reviewed independently</button></div>
<div class="chips" role="group" aria-label="Filter by status"><button type="button" class="chip on" aria-pressed="true" data-filter=""><b>31</b> all</button><button type="button" class="chip" aria-pressed="false" data-filter="designed"><b>6</b> designed</button><button type="button" class="chip" aria-pressed="false" data-filter="implemented"><b>3</b> implemented</button><button type="button" class="chip" aria-pressed="false" data-filter="tested by the team"><b>22</b> tested by the team</button><button type="button" class="chip" aria-pressed="false" data-filter="reproduced externally"><b>0</b> reproduced externally</button><button type="button" class="chip" aria-pressed="false" data-filter="reviewed independently"><b>0</b> reviewed independently</button></div>
<p class="hint">The table is wider than this screen. Scroll it sideways.</p>
<div class="tbl"><table id="claims">
<thead><tr><th data-col="0" data-num="1">#</th><th data-col="1">Claim</th><th data-col="2" data-status="1">Status</th><th data-col="3">Version or commit</th><th data-col="4">Reproducible test</th><th data-col="5">Result, date, machine</th><th data-col="6">Independent verification</th></tr></thead>
<tbody>
<tr data-status="tested by the team"><td class="n">1</td><td class="claim">A new mining program every hour, compiled by the miner, with no human in the loop and no pause in mining<div class="where">Homepage hero and "This hour's program"; litepaper Mining</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">igneum-pow 0.2.0; repo <code>b27da39</code>, <code>1292110</code>, <code>100c5d7</code>; fork <code>devnet-v4</code> <code>6457ca95</code></td><td>The live devnet v4: the node announces <code>next_epoch_seed</code> 150 DAA past the seed score, <code>igneum-miner</code> sends <code>prepare</code> to its worker, the worker builds the next program while the current one mines; Metal (<code>proto-metal/igneum-bench</code>), CUDA and OpenCL workers; bench-log "first hourly program swap on the live devnet"</td><td>Epoch boundary at DAA 3,600 (11:05:07 BST, 4 October 2026) crossed live on three vendors: the Mac M5 Max (Metal) compiled the next program in 82 ms, 449 DAA before the boundary, swapped in 0.01 ms, 26.7 MH/s before and after; the RTX 5090 compiled in 1,285 ms, swapped in 0.00 ms, 121.8 before and 123.4 MH/s after; the integrated AMD chip 2.74 MH/s before and after. 0 restarts, 0 rejected blocks, 0 rebuilds. The epoch seed is the epoch block hash; the delay of row 2 is not wired in. At a later boundary (DAA 18,000) one OpenCL worker on PC 2 stayed on the previous epoch after an app reinstall and answered 514 jobs with a seed mismatch; fixed in the miner (<code>3bfe346f</code>, workers emit a <code>need</code> line), the swap time of that forced prepare not measured</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">1</td><td class="claim">A new mining program every hour, compiled by the miner, with no human in the loop and no pause in mining<div class="where">Homepage hero and "This hour's program"; litepaper Mining</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">igneum-pow 0.2.0; repo <code>b27da39</code>, <code>1292110</code>, <code>100c5d7</code>; fork <code>devnet-v4</code> <code>6457ca95</code></td><td>The live devnet v4: the node announces <code>next_epoch_seed</code> 150 DAA past the seed score, <code>igneum-miner</code> sends <code>prepare</code> to its worker, the worker builds the next program while the current one mines; Metal (<code>proto-metal/igneum-bench</code>), CUDA and OpenCL workers; bench-log "first hourly program swap on the live devnet"</td><td>Epoch boundary at DAA 3,600 (10:05:07 UTC, 4 October 2026) crossed live on three vendors: the Apple M5 Max M5 Max (Metal) compiled the next program in 82 ms, 449 DAA before the boundary, swapped in 0.01 ms, 26.7 MH/s before and after; the RTX 5090 compiled in 1,285 ms, swapped in 0.00 ms, 121.8 before and 123.4 MH/s after; the integrated AMD chip 2.74 MH/s before and after. 0 restarts, 0 rejected blocks, 0 rebuilds. The epoch seed is the epoch block hash; the delay of row 2 is not wired in. At a later boundary (DAA 18,000) one OpenCL worker on PC 2 stayed on the previous epoch after an app reinstall and answered 514 jobs with a seed mismatch; fixed in the miner (<code>3bfe346f</code>, workers emit a <code>need</code> line), the swap time of that forced prepare not measured</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">2</td><td class="claim">The program seed passes through a 10-minute verifiable delay from a certified checkpoint, so nobody can grind the seed<div class="where">Litepaper Mining, vs RandomX ("Closed by a verifiable delay")</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>792776e</code>; <code>proto-vdf/</code></td><td><code>proto-vdf</code> full 10-minute runs and the tamper cases in <code>proto-vdf/README.md</code>; bench-log "proto-vdf"</td><td>Class group 1024-bit: 163,000 squarings per second, 10-min eval 585.4 s, prove 9.1 s on 12 threads, verify 4.47 ms, 516-byte proof; wrong checkpoint, flipped seed bit and T+1 all rejected; grinding model gains 0 blocks per epoch with the delay against +3.62 at a 30% advantage without it. 3 October 2026, Apple M5 Max, one core. Prototype only: not in the node on 4 October either, not reviewed against chiavdf (O-4.1)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">3</td><td class="claim">The dataset is memory-hard: computing an item costs more than loading it, and every hash does 128 distinct dataset reads<div class="where">Litepaper Mining and vs RandomX; homepage vs RandomX ("Memory 2 GB, growing")</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>58a5a63</code> (memory-hard), <code>b27da39</code> (generator 2); igneum-pow 0.2.0 (<code>memhard.rs</code>, <code>generator.rs</code>, <code>accept.rs</code>); spec 01 sections 1.4.2 to 1.4.6; <code>proto-metal/MEMHARD.md</code></td><td><code>proto-metal/igneum-bench --inline-dataset</code> against the honest run at 1 GiB and 256 MiB; <code>igneum-census --gen v2 --warps 64</code> over 20,000 programs; bench-log "memory-hard dataset" and "generator version 2 adopted"</td><td>Honest 45.2 Mhash/s, inline (never reads the dataset) 9.49 Mhash/s, ratio 0.21 at 1 GiB, 0.10 at 256 MiB. 3 October 2026, Apple M5 Max. Generator 2, 4 October 2026: 20,000 programs, 128 static loads on every program, distinct addresses per hash mean 127.9, minimum 120.1; 5.2% of candidates rejected by the acceptance rule. The price of the 128 fresh reads is the hash rate: Apple OpenCL 45.0 MH/s on a version 1 program with 80 distinct loads against 27.5 to 27.9 on version 2; the RTX 5090 229 MH/s on a 104-load version 1 program at 1 GiB (3 October) against 121.8 to 124.2 MH/s mining version 2 on the live devnet (4 October). Apple only for the shortcut ratio (O-1.5); the on-die cache question of ledger M16 is unchanged</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">4</td><td class="claim">The same program produces identical hashes on three GPU vendors, cache and dataset included<div class="where">Litepaper vs RandomX ("Bit-exact on Apple, NVIDIA and AMD, measured"), For miners; homepage</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>f2e903e</code>, <code>0f1fdaf</code> (version 1 packs), <code>b27da39</code> (version 2 packs <code>igneum-genesis-mh</code>, <code>igneum-devnet-v4-epoch0</code>); igneum-pow 0.2.0</td><td>The 96 test vectors of a pack through <code>proto-metal/igneum-bench</code>, <code>proto-cuda/host.cu</code>, <code>proto-opencl/host.c</code>; batch fingerprint at <code>--batch-log2 24</code>; the miner's CPU re-check of every share a GPU worker finds on the devnet; bench-log entries "RTX 5090, memory-hard dataset", "AMD gfx1036", "RTX 5090 through NVIDIA OpenCL", "generator version 2 adopted", "the gfx1036 worker fault"</td><td>Version 1: 96/96 on Apple Metal (M5 Max), NVIDIA CUDA and NVIDIA OpenCL (RTX 5090, Windows), AMD OpenCL (Ryzen 7 9800X3D integrated gfx1036, 1 compute unit), Apple OpenCL, pocl and two CPU references; batch fingerprint <code>98af644e993239e2</code> over 16.7 million nonces identical on the AMD chip and the 5090, 3 October 2026. Version 2: 96/96 on Apple Metal, Apple OpenCL and the CUDA and OpenCL emulators with identical fingerprints; on real NVIDIA and AMD silicon the version 2 vectors have not run as a pack, but both mined accepted blocks on the live devnet with the CPU re-check clean on every share (RTX 5090 at 124.2 MH/s, gfx1036 at 3.3 MH/s), 4 October 2026. The AMD device is an integrated chip; no discrete AMD card and no Intel card has run anything (O-1.15)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">5</td><td class="claim">A CPU verifies one hash in under 10 ms by simulating one warp<div class="where">Litepaper Mining ("about ten milliseconds"), vs RandomX; roadmap gate 2</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>75cac18</code>, <code>b27da39</code>; igneum-pow 0.2.0 (<code>verify.rs</code>)</td><td><code>cargo test</code> and the crate bench in <code>igneum-pow/</code>; bench-log "igneum-pow: Rust crate bit-exact with proto-metal" and "generator version 2 adopted"</td><td>0.411 to 0.579 ms per 32-lane warp steady, 0.41 to 0.87 ms cold, average of 20, 1 GiB dataset, cache held, one M5 Max performance core, 3 October 2026; version 2 units 0.631 ms (average of 20), cold 0.67 to 0.81 ms, 4 October 2026. Gate margin about 16x on this core. Not measured on a 2019-class laptop core (O-1.14)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">6</td><td class="claim">The hash is bound to the header: one nonce serves one header, and a wrong nonce is rejected<div class="where">Spec 1.6; litepaper Mining (implied by "checks a hash")</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>33f7b33</code>, <code>9812466</code>, <code>b27da39</code>; igneum-pow 0.2.0 (<code>bind.rs</code>, bound vectors re-cut for version 2, 39 crate tests)</td><td><code>igneum-miner bad-nonce</code> against a devnet node; <code>igneum-pow hash-bound</code> for the 96-nonce job across the 2^32 lane boundary; bench-log "first devnet blocks on the real lottery hash" and "generator version 2 adopted"</td><td>833 blocks accepted by <code>igneum-lottery-v1-bound</code> on 3 nodes, 0 rejections; <code>bad-nonce</code> gave Reject(BlockInvalid); Metal, OpenCL and CUDA (emulated) workers bit-exact with the crate on the lane-boundary job, 3 October 2026, Apple M5 Max. Version 2: the node's engine reports <code>igneum-lottery-v2-bound</code>, 39 of 39 crate tests, and the live devnet v4 accepts its blocks under it, 4 October 2026</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">7</td><td class="claim">The devnet runs at one block a second<div class="where">Homepage stats ("1 / s"); litepaper Speed; roadmap phase 3</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>9812466</code>, <code>e9328c6</code>, <code>8dae48b</code>; fork <code>devnet-v4</code> <code>dc749905</code></td><td>The merged node's 3-node test network (<code>igneum-devnet-880</code>, 960 s); the live devnet v4 record <code>sim/difficulty/records/live-2026-10-04.csv</code>; the 12-node cloud network's arrival logs; bench-log "devnet-v4 integration", "difficulty rule v2", "first devnet blocks"</td><td>Merged node, 4 October 2026, Apple M5 Max: 1,055 blocks in 960 s, 1.03 blocks/s, sink identical on 3 nodes at 31 of 31 samples, 0 rejected. Live devnet v4 the same day: 49 to 81 blocks a minute while two RTX 5090s joined and left (row 12), 1.1 to 1.2 blocks/s in the oscillating window, then within 1.3% per minute with one PC and the Mac. The 12-node cloud network at one block a second: 644 blocks in a 10-minute window. The 3 October CPU devnet: 1.29 blocks/s over 641 s, 1.03 after the first retarget. The phase 3 gate also asks for proofs under 60 s behind the tip; no proof is on the chain (row 15)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">8</td><td class="claim">Blocks are mined by GPUs on Apple and NVIDIA<div class="where">Homepage live strip; journey phase 3 ("GPU miners on three vendors")</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>9812466</code>, <code>e9328c6</code>, <code>d7e1f89</code>, <code>2309c8d</code>; fork <code>devnet-v4</code></td><td>Metal worker <code>proto-metal/igneum-bench --serve</code> driven by <code>igneum-miner --worker</code>; the live devnet v4 hash-rate record <code>sim/difficulty/records/live-2026-10-04-hashrate.csv</code> (587 worker STATUS lines by run id); bench-log "first devnet blocks", "devnet v4 cut-over", "difficulty rule v2", "first machine on the Igneum Miner app"</td><td>Metal: 506 jobs, 5,636 blocks found and accepted, 0 rejected, 0 CPU/GPU mismatches, 28.2 MH/s wall, 3 October 2026. Live devnet v4, 4 October 2026: PC 1's RTX 5090 at 122 MH/s with 8 identities, PC 2's at 124 MH/s with 8 identities (117 to 119 MH/s inside the one-click app, 34 accepted blocks in its first minute, CPU re-check OK on every share), the Mac's Metal worker at 26.7 MH/s; 17 vote keys signed the first finality lock (row 10); from the afternoon an Apple silicon laptop outside the project at 21.0 MH/s through the app (row 30). Two RTX 5090s and two Apple chips; no other NVIDIA model has mined</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">7</td><td class="claim">The devnet runs at one block a second<div class="where">Homepage stats ("1 / s"); litepaper Speed; roadmap phase 3</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>9812466</code>, <code>e9328c6</code>, <code>8dae48b</code>; fork <code>devnet-v4</code> <code>dc749905</code></td><td>The merged node's 3-node test network (<code>igneum-devnet-880</code>, 960 s); the live devnet v4 record <code>sim/difficulty/records/live-2026-10-04.csv</code>; the 12-node cloud network's arrival logs; bench-log "devnet-v4 integration", "difficulty rule v2", "first devnet blocks"</td><td>Merged node, 4 October 2026, Apple M5 Max: 1,055 blocks in 960 s, 1.03 blocks/s, sink identical on 3 nodes at 31 of 31 samples, 0 rejected. Live devnet v4 the same day: 49 to 81 blocks a minute while two RTX 5090s joined and left (row 12), 1.1 to 1.2 blocks/s in the oscillating window, then within 1.3% per minute with one PC and the Apple M5 Max. The 12-node cloud network at one block a second: 644 blocks in a 10-minute window. The 3 October CPU devnet: 1.29 blocks/s over 641 s, 1.03 after the first retarget. The phase 3 gate also asks for proofs under 60 s behind the tip; no proof is on the chain (row 15)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">8</td><td class="claim">Blocks are mined by GPUs on Apple and NVIDIA<div class="where">Homepage live strip; journey phase 3 ("GPU miners on three vendors")</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>9812466</code>, <code>e9328c6</code>, <code>d7e1f89</code>, <code>2309c8d</code>; fork <code>devnet-v4</code></td><td>Metal worker <code>proto-metal/igneum-bench --serve</code> driven by <code>igneum-miner --worker</code>; the live devnet v4 hash-rate record <code>sim/difficulty/records/live-2026-10-04-hashrate.csv</code> (587 worker STATUS lines by run id); bench-log "first devnet blocks", "devnet v4 cut-over", "difficulty rule v2", "first machine on the Igneum Miner app"</td><td>Metal: 506 jobs, 5,636 blocks found and accepted, 0 rejected, 0 CPU/GPU mismatches, 28.2 MH/s wall, 3 October 2026. Live devnet v4, 4 October 2026: PC 1's RTX 5090 at 122 MH/s with 8 identities, PC 2's at 124 MH/s with 8 identities (117 to 119 MH/s inside the one-click app, 34 accepted blocks in its first minute, CPU re-check OK on every share), the Apple M5 Max's Metal worker at 26.7 MH/s; 17 vote keys signed the first finality lock (row 10); from the afternoon an Apple silicon laptop outside the project at 21.0 MH/s through the app (row 30). Two RTX 5090s and two Apple chips; no other NVIDIA model has mined</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">9</td><td class="claim">Blocks are mined by a GPU on AMD<div class="where">Journey phase 3 ("three vendors")</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>2c4b30f</code> (generic OpenCL worker, <code>--pack</code>), <code>112acf6</code> (fault guards); bound kernel <code>kernel_bound.cl</code> in the pack</td><td><code>igneum-worker-opencl.exe --pack</code> on PC 2's integrated Radeon against the live devnet v4 through the Windows package; bench-log "the gfx1036 worker fault", "first hourly program swap", "first machine on the Igneum Miner app"</td><td>PC 2's integrated gfx1036 (1 compute unit) mined on the live devnet on 4 October 2026: 8 accepted blocks at 3.3 MH/s over 577 s with the CPU re-check clean, and 2.74 MH/s through the hourly program swap with 0 rejected. At about 600 s the AMD runtime began answering every call with success while running nothing (906 jobs became 56,384 in 30 s, 4.3 GH/s of phantom work); not reproduced on Apple OpenCL in 4,565 jobs with 0 leaked objects; the worker and miner now refuse a job 20x faster than the mean or an unchanged output buffer and restart (<code>112acf6</code>), and the next gfx1036 run names the guard that fires. One integrated chip; no discrete AMD card has run anything</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">10</td><td class="claim">Checkpoints lock every 30 s of chain at two thirds of all 30-day weight, and the floor stops conflicting locks in partitions and eclipses for as long as neither side's own new blocks carry it past two thirds of its window (about 10 days of a 30-day window at a 50/50 split)<div class="where">Litepaper Finality, "What Igneum does not claim"; homepage "locked every 30 seconds"</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>a3a9833</code> (2/3 floor, O-3.15), <code>bbb264a</code> (simulation), <code>c16ccf1</code>; fork <code>devnet-v4</code> <code>6457ca95</code> (<code>FLOOR_NUM / FLOOR_DEN</code> 2/3), <code>da1eb889</code> (F17 by-weight sortition, F1 first-month gate <code>min_daa = window</code>); spec 3.3, 3.3.1, 3.7, 3.9</td><td>The live devnet v4 (<code>getFinalityCheckpoints</code>, <code>tools/observer/observer.mjs</code>, <code>/api/checkpoint</code>); <code>sim/finality_v2.py --floor 1.0</code>, scenarios A to L; the three-node, six-voter partition runs <code>igneum-devnet-921</code> to <code>-923</code>; <code>tools/finality-attacks</code> scenarios 1 to 6 and 8; bench-log "first finality lock on the live devnet", "finality floor 2/3", "finality v2 attack harness", "finality fixes F17 and F1"</td><td>Live: the first lock on the live devnet was checkpoint 242 at 12:03:44 BST on 4 October 2026, two hours after genesis (the window and <code>min_daa</code> are 7,200 DAA), with 77.4% of all weight and of active weight signed by 12 aggregated votes from 17 vote keys; <code>observer.mjs</code> saw it 0.7 s after the miner's own lock line. By 13:21 UTC the observer held 280 certificates, indices 241 to 522 (DAA 7,229 to 17,982), 17 to 27 voters, no index with two hashes. Test networks, 4 October 2026, Apple M5 Max: a 4/2 split locked on the 4 side (67.9%) 2 to 8 s after the cut and never on the 2 side, 0 conflicts; a 3/3 split locked on neither side for 150 s with 0 conflicts, where the 3 October floor (56.7%) would have locked both sides at 76 and 106 s; the rule guarantees one lock history for partitions shorter than the window bound W / (3R) (200 s on that test network's 1,800-DAA window, about 40 minutes on the devnet, about 10 days at the 30-day mainnet window); beyond that bound each side can reach two thirds of its own window, so the next finality rule freezes the weight table at the last certified checkpoint and pauses instead. Simulator with the 2/3 floor: 0 conflicts up to a 33% equivocator (34% splits a 50/50 partition), silent weight pauses locks from 34%, a 50/50 partition locks alone from day 10.1. Harness: equivocating keys stripped on every node, Sybil dust at zero weight, a pulsed miner's weight equal to its block share (ratio 0.96 to 1.0), the first-month gate stops a young window locking under one key. Not demonstrated: certificate injection on the wire, an eclipse with a private fork, the 2-hour presence window at mainnet length</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">10</td><td class="claim">Checkpoints lock every 30 s of chain at two thirds of all 30-day weight, and the floor stops conflicting locks in partitions and eclipses for as long as neither side's own new blocks carry it past two thirds of its window (about 10 days of a 30-day window at a 50/50 split)<div class="where">Litepaper Finality, "What Igneum does not claim"; homepage "locked every 30 seconds"</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>a3a9833</code> (2/3 floor, O-3.15), <code>bbb264a</code> (simulation), <code>c16ccf1</code>; fork <code>devnet-v4</code> <code>6457ca95</code> (<code>FLOOR_NUM / FLOOR_DEN</code> 2/3), <code>da1eb889</code> (F17 by-weight sortition, F1 first-month gate <code>min_daa = window</code>); spec 3.3, 3.3.1, 3.7, 3.9</td><td>The live devnet v4 (<code>getFinalityCheckpoints</code>, <code>tools/observer/observer.mjs</code>, <code>/api/checkpoint</code>); <code>sim/finality_v2.py --floor 1.0</code>, scenarios A to L; the three-node, six-voter partition runs <code>igneum-devnet-921</code> to <code>-923</code>; <code>tools/finality-attacks</code> scenarios 1 to 6 and 8; bench-log "first finality lock on the live devnet", "finality floor 2/3", "finality v2 attack harness", "finality fixes F17 and F1"</td><td>Live: the first lock on the live devnet was checkpoint 242 at 11:03:44 UTC on 4 October 2026, two hours after genesis (the window and <code>min_daa</code> are 7,200 DAA), with 77.4% of all weight and of active weight signed by 12 aggregated votes from 17 vote keys; <code>observer.mjs</code> saw it 0.7 s after the miner's own lock line. By 13:21 UTC the observer held 280 certificates, indices 241 to 522 (DAA 7,229 to 17,982), 17 to 27 voters, no index with two hashes. Test networks, 4 October 2026, Apple M5 Max: a 4/2 split locked on the 4 side (67.9%) 2 to 8 s after the cut and never on the 2 side, 0 conflicts; a 3/3 split locked on neither side for 150 s with 0 conflicts, where the 3 October floor (56.7%) would have locked both sides at 76 and 106 s; the rule guarantees one lock history for partitions shorter than the window bound W / (3R) (200 s on that test network's 1,800-DAA window, about 40 minutes on the devnet, about 10 days at the 30-day mainnet window); beyond that bound each side can reach two thirds of its own window, so the next finality rule freezes the weight table at the last certified checkpoint and pauses instead. Simulator with the 2/3 floor: 0 conflicts up to a 33% equivocator (34% splits a 50/50 partition), silent weight pauses locks from 34%, a 50/50 partition locks alone from day 10.1. Harness: equivocating keys stripped on every node, Sybil dust at zero weight, a pulsed miner's weight equal to its block share (ratio 0.96 to 1.0), the first-month gate stops a young window locking under one key. Not demonstrated: certificate injection on the wire, an eclipse with a private fork, the 2-hour presence window at mainnet length</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">11</td><td class="claim">Hashrate that arrived today has almost no vote: ten days of the whole network's hashrate to reach a third of the weight, twenty for two thirds; 51% never reaches two thirds while honest miners stay<div class="where">Litepaper Finality; homepage firsts</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>bbb264a</code>; <code>sim/finality_v2.py</code></td><td>Scenario B of <code>sim/finality_v2.py</code>, seeds 7 and 11</td><td>share(t) = (t/30) x a/(1+a) holds to 0.04 points; a renter equal to the whole honest network (a = 1) crosses 1/3 on day 20 and never reaches 2/3; a = 9 crosses 1/3 on day 11.1 and 2/3 on day 22.2. The ten-day figure is a = infinity, honest miners gone. 3 October 2026, Apple M5 Max. A model with 1,000 Pareto keys and no DAG; the live devnet's window is two hours old, so the claim has no live measurement yet</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">12</td><td class="claim">The difficulty rule recovers from a hashrate step within minutes, where Kaspa's sampled rule never settles. A step inside an epoch set the rule oscillating on the live devnet on 4 October 2026; rule v2 removes it in the simulator and on a test network and is built but not yet rolled out<div class="where">Spec 2.3; litepaper Speed (implied); bench page</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>e9328c6</code>, <code>abb5a5d</code> (attacks), <code>67bf226</code> (rule v2); fork <code>difficulty</code> branch (timestamp fix) and <code>devnet-v4</code> <code>a21ff239</code> (<code>difficulty_v2_activation_daa</code>, <code>REF_WINDOW_V2 = 600</code>); <code>sim/difficulty/sim.py --live</code></td><td>The live record <code>sim/difficulty/records/live-2026-10-04.csv</code> (8,090 headers, <code>pull_live.py</code>) and the hash-rate record beside it; <code>sim/difficulty/sim.py</code> on the synthetic set and the DAG replay; <code>sim/difficulty/attacks/attacks.py</code>; <code>sim/difficulty/testnet_v2.py</code> (3 nodes, activation at DAA 900); <code>cargo test --release -p kaspa-consensus --lib difficulty</code> (15 pass); bench-log "difficulty controller", "difficulty rule under attack", "timestamp attack fixed", "difficulty rule v2"</td><td>Live devnet v4, 4 October 2026 (UTC): a second RTX 5090 joining 7 minutes into an epoch (about 152 to 280 MH/s) hardened the difficulty 70M to 144M in 90 s and then swung by about a third for 40 minutes around the true level of 139M while the epoch-long reference lane carried the join; that card leaving for 4 minutes eased 116M to 67M and back to 106M; the epoch boundary with both PCs restarting took 152M to 77M in 3 minutes, after which the rule held within 1.3% per minute with no flips. Cause: the reference lane covered the whole epoch, so a mid-epoch step polluted it for the hour and the 25% trigger flipped on the short lane's noise. The DAG replay reproduces the record (std of log difficulty 0.115 against 0.134, 4.3 peaks against 4). Rule v2 (reference window 600 DAA) on the replay: std 0.026, 0 flips, mean 142.6M against 139M true; on a 3-node test network the v2 nodes eased a leave with no peak and held a rejoin within 3% after 60 s, and a node without the activation height forked off at it as designed. Rule v2 rolled onto the 12-node cloud network on 4 October (all nodes crossed the height on one chain; a hash-rate step then settled in 160 to 270 s with no swing) and activates on the devnet at DAA 33,000 the same evening. Timestamp forging (ledger M23) fixed the same day: a 50% forger drifts the rate under 1.1% where the 3 October rule gave it a 9.9x difficulty. Simulator, settled seconds: x50 step 62 to 66 (Kaspa 1,542), /50 step 657 to 753 (Kaspa 12,296). Apple M5 Max under load 7 to 442; the DAG model is fitted on one scale; the pool hopper's 0.7-point excess over Kaspa's rule stays open</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">13</td><td class="claim">Every node executes the ordered transactions natively and reaches the same state root<div class="where">Litepaper Proving ("Every node executes ... natively"), Building ("runs on Igneum unchanged")</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>f5f8c80</code>, <code>8dae48b</code>; fork <code>devnet-v4</code> <code>dc749905</code>; revm 43.0.3</td><td><code>node tools/evm-smoke/smoke.mjs</code> against a 3-node <code>igneumd</code>; <code>igneum-exec-diff seq.json</code>; bench-log "execution layer devnet v3" and "devnet-v4 integration"</td><td>Simnet, 3 October 2026: 87 of 87 viem checks, state roots identical on 3 nodes at four heights, 57 executed and 19 skipped transactions agree with plain revm, 0 mismatches. Merged node on real proof of work, 4 October 2026: 84 of 85 checks (the miss needs parallel blocks the network did not produce in 36 s), 59 transfers in 10 chain blocks, state roots identical on 3 nodes, <code>igneum-exec-diff</code> 0 mismatches over 59 transactions; the live devnet v4 runs this execution layer. Apple M5 Max. The prover is a stub; state is rebuilt from genesis at start; no EVM transaction relay between nodes</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">14</td><td class="claim">Ethereum bytecode runs unchanged, with the documented differences of spec 7.1<div class="where">Homepage Build card; litepaper Building</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">as row 13; fixes <code>F-exec-A</code>, <code>F-exec-B</code> (spec 7.5)</td><td><code>tools/evm-smoke/smoke.mjs</code>: deploy via viem, <code>increment</code>, <code>hashLoop</code>, <code>eth_estimateGas</code>, <code>eth_getLogs</code>; <code>tools/exec-attacks</code> scenarios 1 and 3; bench-log "execution layer attack fixes"</td><td>Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration, 3 October 2026. 4 October 2026: a transaction that would cross the block's proving budget is refused by the mempool and, if forced in, aborted and charged with its nonce advanced (25 of 25 checks; 30 of 30 malformed cases). Apple M5 Max. The <code>Prover</code> precompile, proof records and the shard planner are not in the node</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">15</td><td class="claim">Every block is proven, with the proof landing within about a minute at launch<div class="where">Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>d7e1f89</code> (GPU proof), <code>e01a3cc</code>, <code>292e800</code>, <code>eedd136</code> (<code>proving/igneum-prove</code>: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6</td><td><code>proving/windows-wsl2</code> (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; <code>igneum-prove-host --mode block</code> on <code>proving/fixtures/</code>; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards"</td><td>First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture <code>block-78-increment</code> (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in <code>docs/benchmarks/proving-e2e.md</code>. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20)</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">16</td><td class="claim">A 12 GB card proves one shard in about 20 s<div class="where">Litepaper Proving ("The proving budget"); roadmap gate 2</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 5.1 (Target), 7.6 (<code>S_p</code> provisional, 7,500,000 pgas = <code>B_p</code> / 4)</td><td><code>PROVE-SHARD.bat</code> on the RTX 5090 (pending); the end-to-end standard in <code>docs/benchmarks/proving-e2e.md</code>; bench-log "proving: devnet v4 shards"</td><td>Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional <code>S_p</code> is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">17</td><td class="claim">The chip resistance target: a chip gains under 2x over a GPU<div class="where">Litepaper Mining, "What Igneum does not claim"; homepage "no chip can be built for it"</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 0.2 (Target); O-1.17</td><td>Public benchmark with a leaderboard by card model and a standing bounty, January 2027 (O-1.17); the on-die-SRAM test on the RTX 5090 (R3.5)</td><td>A target, not a measurement. Review round 3 priced a recompute chip with the 256 MiB cache on die at about 2.4x, approximate, before the usual chip-versus-GPU integer gain; the design answer (cache larger than any die) is open (spec 1.16)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">18</td><td class="claim">The chip resistance measurements: the program is random-access bound, not bandwidth bound, and sits beyond a card's on-chip cache<div class="where">Litepaper Mining ("bound by memory bandwidth", to be corrected), vs RandomX "Measured so far"</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>aba248d</code>, <code>f2a1a64</code>, <code>4b95c5e</code></td><td>RTX 5090 dataset sweep 4 MiB to 1 GiB with <code>proto-cuda/host.cu</code>; bench-log "RTX 5090 first run" and "dataset sweep"</td><td>At 1 GiB: 228.1 Mhash/s, 23.7 G random loads/s, 94.9 GB/s useful against a 1,638 GB/s dataset fill; inside the 96 MiB L2 (4 and 64 MiB) 1,340 to 1,353 Mhash/s, about 5.8x faster; 104 against 128 loads per hash gives 228 against 185 Mhash/s, proportional. 3 October 2026, RTX 5090, Windows, CUDA 12.8, version 1 programs. Prototype dataset 1 GiB against 2 GB at genesis; a pure random-read microbenchmark (R3 chip designer, attack 2) has not run; the sweep has not been repeated on version 2</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">19</td><td class="claim">The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed<div class="where">Litepaper vs RandomX ("Every number above is measured and logged")</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>c52307e</code>, <code>58a5a63</code>, <code>b27da39</code>; <code>proto-metal/TESTS.md</code></td><td><code>proto-metal/igneum-bench --fuzz --edge --stats --determinism --memcheck</code>; <code>--fuzz 2000</code> on the version 2 generator; <code>igneum-census</code>; bench-log "hardening tests", the re-run on the memory-hard dataset, "generator version 2 adopted"</td><td>Version 1: 10,200 random programs, 1,305,600 hashes, 0 mismatches; 14 of 14 edge cases; bit frequency within 2.90 sigma, avalanche mean 31.99 to 32.04 of 32; deterministic fingerprint across 5 runs; every dataset read masked, 3 October 2026. Version 2, 4 October 2026: 2,000 random programs through the Metal cross-check, 8,000 warps, 0 mismatches, 128 loads per hash on every program; 20,000-program census, 5.2% rejected (4.1% static, 1.1% dynamic). Apple M5 Max. Statistics are not a security proof; the edge, stats and memcheck sections were not re-run on version 2 (they do not depend on the generator); the seed derivation review (O-1.4) is open; the fuzz set has run on Metal and the CPU only</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">15</td><td class="claim">Every block is proven, with the proof landing within about a minute at launch<div class="where">Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>d7e1f89</code> (GPU proof), <code>e01a3cc</code>, <code>292e800</code>, <code>eedd136</code> (<code>proving/igneum-prove</code>: shard cutter, MPT witnesses, shard and aggregator guests); SP1 6.8.1; spec 7.2, 7.6</td><td><code>proving/windows-wsl2</code> (SETUP-PROVER, PROVE-BLOCK) on the RTX 5090; <code>igneum-prove-host --mode block</code> on <code>proving/fixtures/</code>; bench-log "proving v0 on the RTX 5090" and "proving: devnet v4 shards"</td><td>First GPU proof of an Igneum block, 4 October 2026, RTX 5090 (WSL2, SP1 cuda, mining paused): fixture <code>block-78-increment</code> (2 transactions), core proof 1.4 s (7.3 MB, verify 0.221 s), compressed proof 2.7 s (1.27 MB, verify 0.038 s), post-state and receipts roots identical to the node's; 15.7x and 20.6x faster than a loaded M5 Max CPU. The same day on that CPU (load 38 to 47): a three-shard block proved shard by shard and aggregated by recursion, 19 min (1,139 s) end to end, 245 to 337 s per compressed shard proof, every proof verified. What is not there: no proof is produced, carried or checked on the chain (the devnet prover is a stub that signs claims), the proving pool pays nobody (row 21), the block proven is far below one shard, and the 60-second figure remains a design target; the pass mark is the standard in <code>docs/benchmarks/proving-e2e.md</code>. Second RTX 5090 run, 4 October 2026 evening (job run-20261004-173115): a full shard at the provisional S_p (6.75 M pgas, 60.8 M cycles) executed in 1.63 s, core proof 8.3 s (18.1 MB), compressed proof 10.9 s (1.27 MB, verify 0.040 s); a two-shard block (13.5 M pgas) proved shard by shard (11.7 s and 10.0 s) and aggregated in 2.2 s, 24 s of GPU stages end to end, every proof verified, six tampered witnesses rejected. The two host defects (an abort after the upload, an idle wait that turned out to be an unbuffered 18 MB proof save through the WSL2 file bridge, 24 minutes) are fixed (ledger P20) 5 October 2026, live devnet with real transactions (bench-log "real transactions, the first non-empty shard proven and paid"): block 72704 shard 0, 29 transfers, 5,800 pgas, proven on PC 2 in 34 s, verified on the Apple M5 Max in 0.297 s and paid 1.7623 IGN, 53 s after the chain block executed; of about 1,400 blocks in the 20-minute window 36 were proven (the one prover takes the newest shard assigned to it), so "every block" is not yet true; a second content shard (72803, all copies skipped) failed the native-execution veto on the exporter's block structure, fixed with fixtures the same day, the node side pending the 0.3.9 rollout 5 October 2026, evening (bench-log "proving v1"): the aggregated segment record, the chain rule and the unproven rule are implemented behind <code>proving_v1_activation_daa</code> (branch proving-v1, not on the devnet before 0.3.11); on the RTX 5090 a chain of 8 consecutive live blocks proved and aggregated by recursion in 135.6 s with the miner on the card (17 s a block, one proof of 1,272,909 bytes attesting all 8, verified in 0.04 s); the 3-node fast-time harness paid a segment record 1.0 s after submission and refused a late one after its deadline (21 checks); the devnet itself, with one prover, carried proofs for 2.4% of blocks over 30 minutes at a block-to-record latency p50 44 s, p99 52 s. The "within about a minute" holds per proven block; "every block" needs 18 mining 5090s or 6 proving-only cards at empty blocks on the measured rates, and the mandatory rule stays off until the share is one</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">16</td><td class="claim">A 12 GB card proves one shard in about 20 s (WITHDRAWN 5 October 2026: a 24 GB card proves a full shard at the adopted size in 4.3 s; 32 GB mines and proves)<div class="where">Litepaper Proving ("The proving budget"); roadmap gate 2</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 5.1 (Target), 7.6 (<code>S_p</code> provisional, 7,500,000 pgas = <code>B_p</code> / 4)</td><td><code>PROVE-SHARD.bat</code> on the RTX 5090 (pending); the end-to-end standard in <code>docs/benchmarks/proving-e2e.md</code>; bench-log "proving: devnet v4 shards"</td><td>Measured on a 32 GB card, not yet on a 12 GB card. A shard at the provisional <code>S_p</code> is 60.8 M SP1 cycles on the prototype pgas table (9 cycles per pgas, 44 per EVM gas; the modexp entry about 100x its SP1 cost); on an RTX 5090 (4 October 2026 evening, job run-20261004-173115) it executed in 1.63 s and its compressed proof took 10.9 s, verified in 0.040 s, so the 32 GB card is inside the 20 s target with margin. Whether a 12 GB card proves it at all, and in what time, is the next measurement (an RTX 3060 and an RTX 5060 Ti 16 GB are on order). A per-shard time can be met by shrinking the shard, so the project does not use it as a pass mark 5 October 2026, evening (bench-log "proving v1", the S_p curve): measured on the RTX 5090 with SP1 6.8.1's GPU prover, the card to itself, 1-s nvidia-smi samples: an empty shard 13,874 MiB and 2.2 s; a full shard at the ADOPTED v1 budget (30,000 pgas, 4.7 M cycles) 20,434 MiB and 4.3 s; the full prototype shard (6.75 M pgas, 60 M cycles) 28,307 MiB and 10.8 s; beside the miner 15,670 and 30,039 MiB. No environment knob of SP1 moves the 13.9 GB floor and the GPU server has no options of its own, so on this build a 12 GB card proves nothing, a 16 GB card only empty shards, a 24 GB card the adopted full shard alone and beside the miner (22,210 MiB and 13.2 s, measured on the 32 GB card: the 5090's allocation pattern, not yet a run on a 24 GB card) and a 32 GB card the prototype shard beside the miner with 2.5 GB spare. The litepaper line now says so; the 12 GB gate returns when a prover build with a smaller floor is measured on a 12 GB card</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">17</td><td class="claim">The chip resistance claim: the strongest recompute chip under 1x per chip against an RTX 5090; the stored-dataset chip 1.2x per chip and 5x to 9x per joule in the model (2.1x to 4.8x by the Ethash precedent); the latency-shadow lever, measured and in its gates, brings it to about 2x<div class="where">Homepage hero and litepaper abstract (draft (a) of <code>docs/plans/counter-asic-3-status.md</code> section 6, chosen 6 October 2026), litepaper "What Igneum does not claim"</div></td><td><span class="st st-0">tested by the team (the model), designed (the target)</span></td><td class="mono">program class v3 (Counter ASIC 2.0, 5 October 2026): branches ca2-v3 d233fa1 and after, ca2-mixer 1ab8b21, ca2-era 78c0ee4; <code>docs/analysis/chip-model-v3.md</code>, <code>docs/analysis/sram-mirror.md</code>, <code>docs/analysis/scratch-soundness.md</code></td><td>The m16 recompute model re-run on the measured v3 rates and verifier times; the on-die-cache chip row</td><td>The on-die-cache recompute chip against the RTX 5090's measured 136.1 MH/s: class v2 2.4x; class v3 (mixer x8) 0.31x bare, 0.92x with a 3x fixed-function allowance (approximate), 0.76x at equal silicon; margin 8% on the allowance, 9% on the budget. 5 October 2026, M5 Max, RTX 5090, RX 9070 XT. The 2x target is a target: no chip has been built; the bounty stands (O-1.17)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">18</td><td class="claim">The chip resistance measurements: the program is latency-bound (random reads), not bandwidth-bound, on every card we own, and sits beyond a card's on-chip cache<div class="where">Litepaper Mining ("waits on memory latency, not on maths or bandwidth"), vs RandomX; the numbers page</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">readwidth e752fc7 (<code>docs/plans/read-width.md</code>), ca2-era 78c0ee4, ca2-cache 2de19e5 (<code>docs/plans/hot-table.md</code>)</td><td>The dependent-read probes at 32 to 1,024 MiB and the hash rate per class on the three cards; the latency-bound share = rate over the probe ceiling per load</td><td>Latency-bound share at the 1 GiB dataset: RTX 5090 0.96 (v2) and 1.01 (v3), RX 9070 XT 0.87 and 0.95, M5 Max 1.01 and 1.06; wider reads do not close the AMD gap (the 9070 XT does 2.4 G dependent reads per second at every width; the 5090 goes bandwidth-bound at 64 B, share 0.58); a 32 to 96 MiB hot table is not kept resident by any card while the dataset streams (g 0.80 to 0.87 in the added form). 5 October 2026</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">19</td><td class="claim">The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed; class v3 bit-exact on the three vendors<div class="where">Litepaper vs RandomX ("Every number above is measured and logged"), the numbers page</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">ca2-mixer 1ab8b21 (<code>tests/mixer.rs</code>, <code>tests/scratch.rs</code>), ca2-era 78c0ee4, ca2-soundness a465881 (<code>docs/analysis/scratch-soundness.md</code>), <code>igneum-pow/tests/packs.rs</code></td><td>The crate suite (53 + 4 + 19 + 7), the Metal fuzz, edge, stats and determinism runs on the v3 construction, the pack vectors and 2^24 fingerprints on Metal, Apple OpenCL, the RTX 5090 and the RX 9070 XT, the 1,024-hash CPU re-check per card</td><td>Class v3 (mixer x8 + era): 200-program fuzz 200 of 200 on Metal, every tenth on Apple OpenCL; the pinned v3 packs 3/3 + 3/3 and 96 of 96 lanes on Metal and Apple OpenCL; the six era packs' fingerprints equal on the three vendors (PC 1 job run-ca2-era-pc1-20261005, 5 October 2026); the v2 exports byte-identical on the v3 crate; the final-class PC rows and the G2 re-check: job run-ca2-era-pc1b-20261005 (pending at the time of writing)</td><td class="iv">none yet</td></tr>
<tr data-status="implemented"><td class="n">20</td><td class="claim">No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%)<div class="where">Homepage stats and Economics tiles; litepaper Supply, Economics</div></td><td><span class="st st-1">implemented</span></td><td class="mono">repo <code>6ac80a3</code>; fork "igneum-node devnet v0"; <code>consensus/core/src/igneum.rs</code>, <code>coinbase.rs</code></td><td><code>cargo test -p kaspa-consensus-core igneum</code> (8 pass: subsidy table, ramp, split, cap) and <code>cargo test -p kaspa-consensus coinbase</code> (8 pass); <code>igneum-miner inspect 40</code>; bench-log "igneum-node devnet v0"</td><td>Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the <code>igneum-proving-pool-v0</code> output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">21</td><td class="claim">The proving pool's 20% reaches shard provers and aggregators<div class="where">Litepaper Economics; homepage "20% provers"</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 5.3; <code>proving/igneum-prove</code> carries the prover's payout address in every shard proof (ledger P12)</td><td>None. The pool output exists (row 20); the payout from it against proof records is unwritten</td><td>The escrow accumulated on the simnet (92.55 IGN at the end of the v3 run) and nothing can draw it. Rule decided: per block, divided among shards by consensus proving cost, sortition to 8 provers for 10 s then open (spec 7.2). The economy model of 4 October 2026 (<code>sim/economy</code>, 1,000 operators, 30 days) kept every block proven within 60 s under six stress scenarios; a model, not hardware</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">21</td><td class="claim">The proving pool's 20% reaches shard provers and aggregators<div class="where">Litepaper Economics; homepage "20% provers"</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">spec 5.3; <code>proving/igneum-prove</code> carries the prover's payout address in every shard proof (ledger P12)</td><td>None. The pool output exists (row 20); the payout from it against proof records is unwritten. Since 5 October 2026: the payout rule is live on the devnet (<code>proving.rs shard_payouts</code>, the carrying segment pays the first valid record per shard its part of the segment's pool credit)</td><td>The escrow accumulated on the simnet (92.55 IGN at the end of the v3 run) and nothing can draw it. Rule decided: per block, divided among shards by consensus proving cost, sortition to 8 provers for 10 s then open (spec 7.2). The economy model of 4 October 2026 (<code>sim/economy</code>, 1,000 operators, 30 days) kept every block proven within 60 s under six stress scenarios; a model, not hardware Live devnet, 5 October 2026: 388 shards paid by 16:02 UTC, 446.13 IGN from the pool to PC 2's payout address, 0.8813 IGN per mergeset block of the proven segment (bench-log entries of 5 October: "the first shards proven, verified and paid" and "real transactions, the first non-empty shard proven and paid")</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">22</td><td class="claim">The base fee is burned in full and the priority fee splits 80% to the miner and provers, 20% to the apps whose code ran<div class="where">Homepage Economics caption and Build card; litepaper "Where fees go"</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>f5f8c80</code>; fork worktree <code>vendor/igneum-node-exec</code></td><td><code>tools/evm-smoke/smoke.mjs</code> receipt checks; bench-log "execution layer devnet v3"</td><td>Transfer receipt: <code>burnedProvingFee</code> 200 gwei, <code>minerTip</code> 16,800 gwei (80%), unregistered developer share 4,200 gwei burned; contract call: 80% to the miner, 20% credited to the payee the constructor registered, balance delta equal. 3 October 2026, Apple M5 Max simnet. The provers' part of the 80% is not split out (no provers exist); the base fee stayed at the 1 gwei floor throughout</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">23</td><td class="claim">No fee to any team, foundation or fund; 0 admin keys in consensus<div class="where">Homepage Economics tiles and caption; litepaper "No fund, no foundation" and Governance</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 5.5, 5.6 (decided 3 October 2026); spec 08</td><td>Reading: no coinbase output, fee route or consensus key in the fork names any party (<code>coinbase.rs</code>, <code>docs/fork-divergence.md</code>)</td><td>The emission code has two outputs (row 20) and the fee code has three routes (row 22), none to a team. The 1% fee of the official client is a client setting, not a protocol rule, and is not implemented. The release key of spec 08 signs client updates (the Igneum Miner app's over-the-air manifest since 4 October 2026, Ed25519) and holds no consensus power; its custody policy is open (O-8.1)</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">24</td><td class="claim">External proving jobs pay 90% to the provers who delivered and burn 10%, once settled in IGN<div class="where">Homepage "IGN burned from jobs, phase two"; litepaper Proving and Economics</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 5.4</td><td>None. Needs the proof bridge (spec 7.3, phase two) and the settlement switch (O-5.2)</td><td>At launch jobs are paid on the customer's chain in the customer's currency and nothing is burned (ledger P10). No job market code exists</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">25</td><td class="claim">The 4 billion cap, halving every two years, with a 30-day ramp from 10%<div class="where">Homepage "4B IGN hard cap"; litepaper Supply and the emission chart</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>6ac80a3</code>; fork <code>consensus/core/src/igneum.rs</code></td><td><code>cargo test -p kaspa-consensus-core igneum</code>; bench-log "igneum-node devnet v0"</td><td>Ramp day 0 paid 10.03% of the full rate (317,767,704 units at DAA 806); the schedule table and the cap assert in the crate's own tests. 3 October 2026, Apple M5 Max. Base unit (8 or 18 decimals) is open (O-2.6); the spec was changed to follow the code's 365.25-day year (ledger E9) and a test that reads the published numbers back is still owed</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">26</td><td class="claim">A phone or browser verifies the chain from a locked checkpoint, at about 3.44 MB per day in checkpoint mode<div class="where">Homepage "Browser checks Igneum" card; litepaper Building ("Light clients"), firsts row 6</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 10 (10.5 bytes per day: 3.44 MB at 1,000 voters, 6.68 MB at 10,000, derived, approximate); repo <code>f874f80</code> for the browser card; <code>site/api/checkpoint.mjs</code></td><td>None for the byte figure; <code>site/verify/</code> for the card against <code>/api/checkpoint</code>. BLS verification on a phone and in WebAssembly is O-10.3; the full-header mode on a phone is O-10.4</td><td>Since 12:03 BST on 4 October 2026 the homepage card verifies the live devnet's own certificates in the tab (index 522 with 27 voters at 13:42 UTC), BLS aggregate against the voter list the node serves, light client v0; before that it verified the 3 October test network's. The byte figure is arithmetic on designed sizes (header 400 bytes, proof 400 bytes), measured nowhere; the execution proof the card would also check is not on the chain (row 15)</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">26</td><td class="claim">A phone or browser verifies the chain from a locked checkpoint, at about 3.44 MB per day in checkpoint mode<div class="where">Homepage "Browser checks Igneum" card; litepaper Building ("Light clients"), firsts row 6</div></td><td><span class="st st-0">designed</span></td><td class="mono">spec 10 (10.5 bytes per day: 3.44 MB at 1,000 voters, 6.68 MB at 10,000, derived, approximate); repo <code>f874f80</code> for the browser card; <code>site/api/checkpoint.mjs</code></td><td>None for the byte figure; <code>site/verify/</code> for the card against <code>/api/checkpoint</code>. BLS verification on a phone and in WebAssembly is O-10.3; the full-header mode on a phone is O-10.4</td><td>Since 11:03 UTC on 4 October 2026 the homepage card verifies the live devnet's own certificates in the tab (index 522 with 27 voters at 13:42 UTC), BLS aggregate against the voter list the node serves, light client v0; before that it verified the 3 October test network's. The byte figure is arithmetic on designed sizes (header 400 bytes, proof 400 bytes), measured nowhere; the execution proof the card would also check is not on the chain (row 15)</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">27</td><td class="claim">The node survives malformed input, floods, withholding, partitions and eclipses<div class="where">Litepaper Speed ("GHOSTDAG, the BlockDAG consensus proven on Kaspa"); spec 2</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>394030c</code>, <code>8dae48b</code>, <code>6b5bd92</code>; fork worktree <code>vendor/igneum-node-harness</code> and <code>devnet-v4</code>; <code>tools/harness/</code>; <code>infra/cloud-devnet/experiments/partition.sh</code></td><td><code>tools/harness/</code> against a private <code>igneumd</code> test network; the merged node's harness scenarios 2 and 5; the cloud network's 10-minute partition of Singapore (<code>results/2026-10-04/partition-sin-20261004-110906/partition.md</code>); bench-log "consensus attack harness", "devnet-v4 integration"</td><td>3 October 2026, Apple M5 Max: 63 malformed cases, node up on every one; withholding at 10% to 45% within 2 sigma of share; partitions of 120 s to 3,700 s healed to one chain in 10 s; eclipse victims rejoined in 10 s; 50x floods left template p95 under 4 ms; one FAIL, a 45% withholder releasing every 20 blocks took 50.7% of blues (bound 47.4%). Merged node, 4 October 2026: 63 cases, node up, 0 cache builds; the 10 s timestamp floor and future bound exact. Cloud network, 4 October 2026: 12 nodes in five locations on their own chain, Singapore cut off by iptables for 10 minutes; the two minority nodes adopted the majority chain 10 and 14 s after the heal with reorgs of 445 and 516 blocks, the majority's deepest reorg was 2 blocks, 0 conflicting locks (none were possible: the weight window stood at DAA 3,030 of 7,200). CPU miners only; the finality rules under partition are row 10</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">28</td><td class="claim">Headers are validated cheaply before the lottery engine runs, so forged timestamps cannot force 256 MiB cache builds<div class="where">Spec 2.4; ledger M15</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>0953ec7</code>, <code>8dae48b</code>; fork worktree <code>vendor/igneum-node-r3</code> branch <code>r3-fixes</code> at <code>5166ee26</code>, merged into <code>devnet-v4</code></td><td><code>measure_m15_attack_before_and_after</code> (ignored test, release, <code>--features igneum-pow</code>); kaspa-pow 8, header_processor 1, p2p <code>pow_guard</code> 2 tests; harness scenario 5 on the merged node</td><td>50 forged headers: before, 50 cold builds in 10,595 ms and the live day evicted; after, 0 builds, all 50 rejected in 14 ms, 3 October 2026, Apple M5 Max under load 60 to 110. Merged node, 4 October 2026: 63 harness cases with 0 cache builds (the node log shows one build, the honest day) and the M15 p2p cases disconnected by the strike guard; the live devnet v4 runs it. Measured through the validate path with <code>skip_proof_of_work</code>, not the daemon RPC</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">29</td><td class="claim">Blocks reach every node well inside GHOSTDAG's delay bound across continents<div class="where">Litepaper Speed (GHOSTDAG at one block a second); spec 03 C1 (lock latency); <code>infra/cloud-devnet/README.md</code></div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>6b5bd92</code>; <code>infra/cloud-devnet/experiments/latency.sh</code>, <code>analyze.py</code>; the Linux cross-build <code>infra/cross/build-linux.sh</code></td><td>12 <code>igneumd</code> nodes on Hetzner VMs in Helsinki, Falkenstein, Ashburn, Hillsboro and Singapore (own chain <code>igneum-devnet-20</code>, one CPU trickle miner each), a ping matrix, then 10 minutes of per-node arrival logs joined on block hash; <code>results/2026-10-04/latency/propagation.md</code> and <code>rtt-by-region.md</code></td><td>644 blocks in the window, 642 seen by at least 80% of nodes; arrival at a node minus the first arrival anywhere: p50 343 ms, p90 497 ms, p99 666 ms, max 2,313 ms; by region p50 239 ms (Falkenstein) to 413 ms (Singapore), p90 455 to 632 ms; inter-region RTT 35 ms (Helsinki to Falkenstein) to 289 ms (Ashburn to Singapore); first arrival minus header time median 490 ms. 4 October 2026. The network is the project's own: 12 nodes not 20 (a new account's limits), CPU hash rate only, clocks by chrony, one evening of data; the 5 s bound behind GHOSTDAG k is a design parameter this run did not challenge</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">30</td><td class="claim">One click: install, press start, the card mines; the app looks after its node<div class="where">Homepage Mine section ("One click: install, press start"); litepaper "One click, for everyone else"; journey phase 5</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>3bb50d6</code>, <code>2c4b30f</code>, <code>6461540</code> (package 0.3.0: prebuilt NVRTC CUDA worker and generic OpenCL worker, driver only), <code>a1a33cb</code>, <code>7c794df</code>, <code>0d4498e</code>, <code>6c083db</code> (Igneum Miner 0.3.0), <code>78903cd</code> (0.3.1, over-the-air updates)</td><td><code>Igneum-Miner-Setup-0.3.0.exe</code> (runner-built, unsigned) on a Windows PC with an RTX 5090 and no toolchain; <code>proto-cuda/nvrtc/emu/serve-check.sh</code> on the Mac; <code>proto-cuda/windows-app/TEST.md</code>; bench-log "one-click Windows workers", "first machine on the Igneum Miner app", "a node 60 s behind the clock is silently dead", "the gfx1036 worker fault"</td><td>Four machines by 15:45 BST on 4 October 2026: PC 2, then PC 1 (RTX 5090 at 110 MH/s under the 80% power cap), the project's Apple M5 Max (25 MH/s) and the outside Apple silicon laptop (row 29), all on Igneum Miner 0.3.1. The NVRTC worker compiled the pack on the card with no toolchain installed and mined at 124.2 MH/s, equal to the nvcc-built worker, 0 rejected, CPU re-check clean; inside the app 117 to 119 MH/s with 34 accepted blocks in the first minute, the integrated AMD chip at 3.3 MH/s beside it (row 9). Two defects found by the install, both fixed the same hour: a clock 62 s slow after a power cut made the node reject every relayed block for 12 minutes with no visible reason (the app now reads the skew from the node's warnings, the block timestamps over the EVM RPC and an HTTPS Date header, warns over 5 s and blocks Start over 10 s, with a one-click clock sync; checked on the Mac with a fake 60 s skew; a one-line node warning is filed), and the node card said "syncing" while the miner was already accepted. The Mac could only emulate the NVIDIA path (17 of 17 sampled hashes) and the AMD path on Apple OpenCL (15 of 15). Over-the-air updates were dry-run on a private devnet (0.3.0 to 0.3.1 and back), not on a user's machine. The installer is unsigned (SmartScreen "run anyway"). Second machine, the same afternoon: a friend of the project installed Igneum Miner 0.3.1 from the DMG on an Apple silicon laptop with no toolchain and no instructions beyond five steps; the node synced from the seed, the Metal worker reported ready, 33 accepted blocks and 0 rejected in 7 minutes at 21.0 MH/s average, CPU re-check OK on every share, uploads arriving every minute under its per-install id. That laptop is not the project's hardware, but the result is observed through the project's own log intake and reported by the project, so it stays tested by the team until an outsider publishes a run of their own. The devnet's other GPU machines (PC 1 and the Mac) run the same workers through the launcher, not the app</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">29</td><td class="claim">Blocks reach every node well inside GHOSTDAG's delay bound across continents<div class="where">Litepaper Speed (GHOSTDAG at one block a second); spec 03 C1 (lock latency); <code>infra/cloud-devnet/README.md</code></div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>6b5bd92</code>; <code>infra/cloud-devnet/experiments/latency.sh</code>, <code>analyze.py</code>; the Linux cross-build <code>infra/cross/build-linux.sh</code></td><td>12 <code>igneumd</code> nodes on cloud VMs in Helsinki, Falkenstein, Ashburn, Hillsboro and Singapore (own chain <code>igneum-devnet-20</code>, one CPU trickle miner each), a ping matrix, then 10 minutes of per-node arrival logs joined on block hash; <code>results/2026-10-04/latency/propagation.md</code> and <code>rtt-by-region.md</code></td><td>644 blocks in the window, 642 seen by at least 80% of nodes; arrival at a node minus the first arrival anywhere: p50 343 ms, p90 497 ms, p99 666 ms, max 2,313 ms; by region p50 239 ms (Falkenstein) to 413 ms (Singapore), p90 455 to 632 ms; inter-region RTT 35 ms (Helsinki to Falkenstein) to 289 ms (Ashburn to Singapore); first arrival minus header time median 490 ms. 4 October 2026. The network is the project's own: 12 nodes not 20 (a new account's limits), CPU hash rate only, clocks by chrony, one evening of data; the 5 s bound behind GHOSTDAG k is a design parameter this run did not challenge</td><td class="iv">none yet</td></tr>
<tr data-status="tested by the team"><td class="n">30</td><td class="claim">One click: install, press start, the card mines; the app looks after its node<div class="where">Homepage Mine section ("One click: install, press start"); litepaper "One click, for everyone else"; journey phase 5</div></td><td><span class="st st-2">tested by the team</span></td><td class="mono">repo <code>3bb50d6</code>, <code>2c4b30f</code>, <code>6461540</code> (package 0.3.0: prebuilt NVRTC CUDA worker and generic OpenCL worker, driver only), <code>a1a33cb</code>, <code>7c794df</code>, <code>0d4498e</code>, <code>6c083db</code> (Igneum Miner 0.3.0), <code>78903cd</code> (0.3.1, over-the-air updates)</td><td><code>Igneum-Miner-Setup-0.3.0.exe</code> (runner-built, unsigned) on a an RTX 5090 on Windows with an RTX 5090 and no toolchain; <code>proto-cuda/nvrtc/emu/serve-check.sh</code> on the Apple M5 Max; <code>proto-cuda/windows-app/TEST.md</code>; bench-log "one-click Windows workers", "first machine on the Igneum Miner app", "a node 60 s behind the clock is silently dead", "the gfx1036 worker fault"</td><td>Four machines by 14:45 UTC on 4 October 2026: PC 2, then PC 1 (RTX 5090 at 110 MH/s under the 80% power cap), the project's Apple M5 Max (25 MH/s) and the outside Apple silicon laptop (row 29), all on Igneum Miner 0.3.1. The NVRTC worker compiled the pack on the card with no toolchain installed and mined at 124.2 MH/s, equal to the nvcc-built worker, 0 rejected, CPU re-check clean; inside the app 117 to 119 MH/s with 34 accepted blocks in the first minute, the integrated AMD chip at 3.3 MH/s beside it (row 9). Two defects found by the install, both fixed the same hour: a clock 62 s slow after a power cut made the node reject every relayed block for 12 minutes with no visible reason (the app now reads the skew from the node's warnings, the block timestamps over the EVM RPC and an HTTPS Date header, warns over 5 s and blocks Start over 10 s, with a one-click clock sync; checked on the Apple M5 Max with a fake 60 s skew; a one-line node warning is filed), and the node card said "syncing" while the miner was already accepted. The Mac could only emulate the NVIDIA path (17 of 17 sampled hashes) and the AMD path on Apple OpenCL (15 of 15). Over-the-air updates were dry-run on a private devnet (0.3.0 to 0.3.1 and back), not on a user's machine. The installer is unsigned (SmartScreen "run anyway"). Second machine, the same afternoon: a friend of the project installed Igneum Miner 0.3.1 from the DMG on an Apple silicon laptop with no toolchain and no instructions beyond five steps; the node synced from the seed, the Metal worker reported ready, 33 accepted blocks and 0 rejected in 7 minutes at 21.0 MH/s average, CPU re-check OK on every share, uploads arriving every minute under its per-install id. That laptop is not the project's hardware, but the result is observed through the project's own log intake and reported by the project, so it stays tested by the team until an outsider publishes a run of their own. The devnet's other GPU machines (PC 1 and the Apple M5 Max) run the same workers through the launcher, not the app</td><td class="iv">none yet</td></tr>
<tr data-status="designed"><td class="n">31</td><td class="claim">Card lifetime: a 4 GB card mines about four years and an 8 GB card about twelve, under the dataset's step schedule (2 GB at genesis, doubling at years 4, 12, 28, 60) with the cache freed after the daily build<div class="where">Litepaper Hardware and vs RandomX ("Dataset" row); homepage Mine card and "Memory" row</div></td><td><span class="st st-0">designed</span></td><td class="mono"><code>docs/analysis/card-lifetime-2026-10-05.md</code> (branch card-lifetime 1fecfe2); spec 1.13.3 option (b) recommended to the owner 5 October 2026 (<code>docs/plans/counter-asic-2-rollout.md</code> 6c)</td><td>The per-tier working-set arithmetic of that document (GTX 1650, RTX 3050, RTX 3060, RTX 4090 tiers) against the step schedule</td><td>A design claim: under the continuous mapping (a) a 4 GB card is out within 1 to 1.5 years and an 8 GB card at 6 to 7.5 years, so the sentence is true only under the step schedule (b), which the spec has not yet fixed (O-1.13)</td><td class="iv">none yet</td></tr>
</tbody></table></div>
<p class="note">Click a column heading to sort; click again to reverse. Versions: <code>igneum-pow</code> is the Rust crate at version 0.2.0 (generator version 2, 4 October 2026); repo commits are this repository's; fork commits are the node fork and its worktrees, named by message as the engineering log names them. Source of every number: the <a href="/bench">engineering log</a>. The source of this page is <code>docs/evidence.md</code> in the repository.</p>
<h2>What would move a row</h2>
@ -231,7 +232,7 @@ code{font-family:var(--f-mono);font-size:.92em;background:var(--obsidian);paddin
<tr><td>reproduced externally</td><td>reviewed independently</td><td>A named reviewer's published finding on that version. Funding for review is <code>docs/plans/funding.md</code></td></tr>
<tr><td>any</td><td>the row's status falls back</td><td>A new version of the code or rule the row names</td></tr>
</tbody></table></div>
<p class="asof">Statuses are honest as of 4 October 2026 and change only through this page.</p>
<p class="asof">Statuses are honest as of 6 October 2026, the day this page was generated from docs/evidence.md, and change only through that file.</p>
</main>
<!-- footer:start -->
<footer class="foot">
@ -249,6 +250,7 @@ code{font-family:var(--f-mono);font-size:.92em;background:var(--obsidian);paddin
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -255,6 +255,7 @@ main{padding-bottom:var(--sec)}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -215,6 +215,7 @@ dt{color:var(--ash)}dd{margin:0;font-family:var(--f-mono);font-size:14px;overflo
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

File diff suppressed because one or more lines are too long

1286
site/ledger.html Normal file

File diff suppressed because it is too large Load diff

View file

@ -298,7 +298,7 @@ body.all .pager{display:none}
<article>
<section id="abstract">
<h2>Abstract</h2>
<p class="lead">Igneum is a proof-of-work blockchain built for graphics cards, where NVIDIA cards also prove every block with zero-knowledge proofs and sell proving to other chains. A custom chip gains under 2x, and the model is public; a bounty follows the external review.</p>
<p class="lead">Igneum is a proof-of-work blockchain built for graphics cards, where NVIDIA cards also prove every block with zero-knowledge proofs and sell proving to other chains. The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090. A memory-controller chip that stores the whole dataset reaches 1.2x per chip and, in our model, 5x to 9x per joule; the Ethash chips of this class reached 2.1x to 4.8x. The lever against it, program work in the latency shadow, is measured and in its gates: it brings the chip to about 2x. Sources: the chip model (<code>docs/analysis/chip-model-v3.md</code> section 5, 6 October 2026); the Ethash rows of the ASIC history (<code>docs/analysis/asic-resistance-history.md</code>, Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022); Counter ASIC 3.0 item 8 (100,000 ops per hash: the chip's per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at a chip core equal to the GPU's, the 5090 at 0.2% less rate, gates G1 to G6 in progress). The model is public; the claim is tested by paid independent cryptanalysis and the public benchmark.</p>
<p>It runs the Ethereum virtual machine, so anything built for Ethereum runs on Igneum unchanged. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two. There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining stays open to anyone with a GPU because the mining program changes every hour, so a chip built for one program is useless for the next, and a chip for the whole program space is a GPU without the graphics parts. No scheduled human release is needed to keep it that way. Writing new code, including an emergency fix to the proof system, is the one thing that takes a person, and it activates only on miner signalling.</p>
<div class="stats">
<div class="stat"><div class="v">1 / s</div><div class="k">blocks, rising to 10</div></div>
@ -393,11 +393,11 @@ body.all .pager{display:none}
<thead><tr><th>Layer</th><th>State</th><th>Since</th></tr></thead>
<tbody>
<tr><td>Mining lottery</td><td>A new program every hour on Apple, NVIDIA and AMD cards, compiled ahead, no pause and no rejected block at the boundary</td><td class="num">4 Oct 2026, first live swap</td></tr>
<tr><td>Blocks</td><td>About one a second</td><td class="num">genesis, 3 Oct 2026</td></tr>
<tr><td>Blocks</td><td>About one a second with the full fleet; 0.65 a second over the hour to 16:00 UTC on 6 Oct 2026 with one PC off (the live page's hour count, 2,325 blocks)</td><td class="num">genesis, 3 Oct 2026</td></tr>
<tr><td>Difficulty</td><td>Rule v2, a 600-second reference window, switched on by height under the running chain with no fork and no restart of the chain</td><td class="num">DAA 33,000, 4 Oct 2026</td></tr>
<tr><td>Finality</td><td>Rule v2: a checkpoint every 30 s of chain, locked at two thirds of all 30-day weight. First live lock: checkpoint 242 at 77.4% of all weight, 17 vote keys</td><td class="num">4 Oct 2026</td></tr>
<tr><td>Proving</td><td>v0 active: shards are assigned to miners' keys, proven on their cards, and the records are carried in blocks</td><td class="num">DAA 84,100, 5 Oct 2026</td></tr>
<tr><td>Ember</td><td>The one-click miner on the fleet, version 0.3.5; 0.3.6 staged</td><td class="num">4 Oct 2026, first install</td></tr>
<tr><td>Ember</td><td>The one-click miner on the fleet, version 0.3.13 (6 Oct 2026); the app window still says Igneum Miner</td><td class="num">4 Oct 2026, first install</td></tr>
<tr><td>Wallet</td><td>Igneum Wallet 0.1.1 on macOS</td><td class="num">5 Oct 2026</td></tr>
</tbody>
</table></div>
@ -408,7 +408,7 @@ body.all .pager{display:none}
<section id="mining">
<h2>Mining: a program that never holds still</h2>
<p>Every GPU chain that promised ASIC resistance shipped a fixed algorithm, and a fixed algorithm gets a chip the moment the prize pays for one. Igneum does not have a fixed algorithm.</p>
<p>Each hour the chain derives a seed from a locked checkpoint one epoch back, passes it through a ten-minute verifiable delay so no miner can see which program a seed implies before choosing whether to publish a block, and feeds it to a deterministic generator. The generator emits a random integer program built from what graphics cards are uniquely good at: wide parallel integer maths, shuffles between the 32 lanes of a warp, and random reads over a multi-gigabyte dataset that changes daily, so the program waits on memory latency, not on maths or bandwidth. The memory footprint and instruction count are fixed and only the maths sequence is random, so no hour favours one vendor's cards and nobody gains by grinding the seed. Miners compile the program once per hour. Anyone running a node, a wallet or an exchange checks a hash on an ordinary CPU in under ten milliseconds by simulating one warp, so nobody needs a GPU except to mine. Measured: 0.61 ms per warp on one Apple M5 Max core for class v2 and 2.1 ms for class v3 (the mixer at x8, 5 October 2026, one core at load average 5.5, worst cold unit 2.15 ms), 3.4x the class v2 verifier; the 10 ms gate leaves 4.8x (4.6x on the worst cold unit); a 2019-class laptop core is not yet measured.</p>
<p>Each hour the chain derives a seed from a locked checkpoint one epoch back, passes it through a ten-minute verifiable delay so no miner can see which program a seed implies before choosing whether to publish a block, and feeds it to a deterministic generator. The generator emits a random integer program built from what graphics cards are uniquely good at: wide parallel integer maths, shuffles between the 32 lanes of a warp, and random reads over a multi-gigabyte dataset that changes daily, so the program waits on memory latency, not on maths or bandwidth. Measured: an RTX 5090 hashes at 95 GB/s of useful 4-byte loads against 1,638 GB/s of sequential writes (engineering log, the RTX 5090 entries). The memory footprint and instruction count are fixed and only the maths sequence is random, so no hour favours one vendor's cards and nobody gains by grinding the seed. Miners compile the program once per hour. Anyone running a node, a wallet or an exchange checks a hash on an ordinary CPU in under ten milliseconds by simulating one warp, so nobody needs a GPU except to mine. Measured: 0.61 ms per warp on one Apple M5 Max core for class v2 and 2.1 ms for class v3 (the mixer at x8, 5 October 2026, one core at load average 5.5, worst cold unit 2.15 ms), 3.4x the class v2 verifier; the 10 ms gate leaves 4.8x (4.6x on the worst cold unit); a 2019-class laptop core is not yet measured.</p>
<p>The hash is a lottery, not a general-purpose cryptographic hash. It has to be unpredictable per nonce, free of any shortcut cheaper than honest evaluation, and free of bias a miner can exploit. It does not need preimage or collision resistance. Open: no analysis of the lottery properties exists yet. It is the first job of the external review in phase 1, and until then the hash is a design claim backed by the measurements below.</p>
<div class="tbl"><table>
<thead><tr><th>Clock</th><th>What changes</th><th>Miner update needed?</th></tr></thead>
@ -421,7 +421,7 @@ body.all .pager{display:none}
</tbody>
</table></div>
<p>Three ideas carry the chip resistance. <strong>The hash rewrites itself.</strong> A new program every hour, drawn from the chain. Its memory pattern changes with it. The rules change on a schedule fixed at launch. No release, no vote. <strong>It waits on memory, not maths.</strong> Every hash is a chain of random reads into a table too big for a chip to carry. The wait is the same physics for everyone. <strong>Miners hold the switch.</strong> Spare defences are written into the rules, switched off. A 90% miner signal turns one on. No fork.</p>
<p>No hash has stayed free of chips forever. Igneum does not claim to. It claims the gain is small, the response takes a week, and both are measured. The model is public: <a href="/bench#counter-asic-2-0-the-numbers">the numbers</a>; a bounty follows the external review. Monero has run on RandomX since 2019 with no chip publicly shipped, approximate; that is precedent, not proof.</p>
<p>No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the response takes a week, and both are measured. The model is public: <a href="/bench#counter-asic-2-0-the-numbers">the numbers</a>; the claim is tested by paid independent cryptanalysis and the public benchmark. Monero has run on RandomX since 2019 with no chip publicly shipped, approximate; that is precedent, not proof.</p>
<p>One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.</p>
</section>
@ -437,7 +437,7 @@ body.all .pager{display:none}
<tr><td>Light verification</td><td>256 MB cache on a CPU, milliseconds</td><td>256 MB cache on a CPU (512 MB from year 4), one warp under 10 ms, the gate. Measured 2.1 ms on one Apple M5 Max core for class v3 (3.4x class v2's 0.61 ms); a 2019-class core not yet</td></tr>
<tr><td>Changes over time</td><td>None. A fixed design, unchanged for seven years</td><td>A new program every hour, its memory pattern with it; era draws and reserved families on a schedule fixed at genesis. Nobody touches it</td></tr>
<tr><td>Seed grinding</td><td>Not applicable, the program comes from the hash input</td><td>Closed by a verifiable delay between seed and program</td></tr>
<tr><td>Useful work</td><td>None. Hashing only</td><td>NVIDIA cards with 24 GB or more prove every block and sell proofs to other chains; AMD and Apple cards mine, and a prover for them lands when a zkVM ships one</td></tr>
<tr><td>Useful work</td><td>None. Hashing only</td><td>Every NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server (eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026, <code>docs/analysis/prover-tiers-real-cards.md</code>); they sell proofs to other chains. AMD and Apple cards mine, and a prover for them lands when a zkVM ships one</td></tr>
<tr><td>Track record</td><td>No chip publicly shipped in seven years, approximate</td><td>Zero years. Every number above is measured and logged with the commands that produced it. The specification, reference hash, test vectors and simulators are public now (github.com/igneum-network/spec). The node, the miner and the wallet are in a private repository until the public testnet</td></tr>
</tbody>
</table></div>
@ -446,12 +446,12 @@ body.all .pager{display:none}
<section id="proving">
<h2>Proving: the miners are the provers</h2>
<p>Every Igneum block is proven with a zero-knowledge proof, and the miners produce it. Proving is a useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not, and a phone can check it in milliseconds.</p>
<p>Every Igneum block is proven with a zero-knowledge proof, and the miners produce it. Proving is a useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not. Wrapped for light clients, a phone checks it in milliseconds; the wrapping cost is a phase two measurement. Measured so far, the certificate half only: the browser verifier on the home page checks a devnet finality certificate, one BLS aggregate signature over 16 keys and 21 header hashes, in 139 to 155 ms cold and 58 to 68 ms warm in a phone-sized tab on a laptop core (5 October 2026). No phone has been measured, and no wrapped block proof exists yet.</p>
<h3>How a block gets proven</h3>
<p>Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond. Provers run them on consumer cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch. Because the proof computes the state from the ordered sequence, no node accepts a block with a wrong state root. Full nodes also execute every block natively and reject a proof record whose result differs from their own execution, so a forged proof is a light-client problem and never a chain split. Implemented: the native-execution check on every carried proof record, proving v0 on the devnet (specification section 7). The emergency path for a soundness bug in the proof system is a human one: a new proof-system version is written by people and activates only on miner signalling. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.</p>
<p>Proving needs an NVIDIA card with 24 GB or more (32 GB until the fee switch of 6 October 2026; from it a 24 GB card mines and proves on the same card: 22.2 GB peak measured with the miner on, 5 October 2026). AMD and Apple cards mine. A prover for them lands when a zkVM ships one.</p>
<p>Proving: every NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server. Measured on eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026, <code>docs/analysis/prover-tiers-real-cards.md</code>: the RTX 3060 (12 GB) mines at 23.78 MH/s and proves the v1 shard beside its miner at an 8.9 GB peak in 37.5 s; the RTX 4060 (8 GB) proves it alone at 7.4 GB in 18.4 s; the RTX 4090 (24 GB) proves it on the stock SP1 server in 5.6 s at 17.4 GB. The patched server that fits the smaller cards is not yet in the shipped app. AMD and Apple cards mine. A prover for them lands when a zkVM ships one.</p>
<h3>The proving budget</h3>
<p>Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Measured on 5 October 2026 (an RTX 5090 under SP1 6.8.1's GPU prover, the shard size the chain adopts from its fee switch, 30,000 proving gas, about 4.7 million prover cycles): one full shard proves in 4.3 seconds and needs 20.4 GB of GPU memory with the card to itself, so a 24 GB card proves full shards and a 12 GB or 16 GB card does not on this prover build, whose floor is 13.9 GB for even an empty shard; mining and proving on one card needs 32 GB today (the prototype-size shard beside the miner peaked at 30.1 GB) and 24 GB once the adopted shard size is live (22.2 GB beside the miner, 13.2 seconds a shard, measured on the 32 GB card; a 24 GB card has not run it yet). The old 12 GB gate on the roadmap is withdrawn until a prover build with a smaller floor is measured. The first proofs exist: on 4 October 2026 an RTX 5090 proved a small two-transaction block in 1.4 seconds (2.7 seconds compressed), verified in 0.22 and 0.038 seconds, and a laptop CPU proved a three-shard block end to end in 19 minutes. Later that day the same card proved a full shard at the provisional size, 6.75 million prover gas, which executed in 60.8 million cycles: core proof 8.3 seconds, compressed proof 10.9 seconds, verified in 0.040 seconds; a four-shard block took 44.5 seconds of GPU stages end to end. Since 5 October 2026 shards are assigned and proven on the live devnet. The gate asks for a mid-range card, and an RTX 5090 is not one, so the gate stands open. Once the gate is measured, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface, so Igneum can adopt a better proof system when one exists by a miner-signalled release, and runs for ever on the current one if none is adopted.</p>
<p>Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Measured on 5 October 2026 (an RTX 5090 under SP1 6.8.1's GPU prover, the shard size the chain adopts from its fee switch, 30,000 proving gas, about 4.7 million prover cycles): one full shard proves in 4.3 seconds and needs 20.4 GB of GPU memory with the card to itself, so a 24 GB card proves full shards and a 12 GB or 16 GB card does not on this prover build, whose floor is 13.9 GB for even an empty shard; mining and proving on one card needs 32 GB today (the prototype-size shard beside the miner peaked at 30.1 GB) and 24 GB once the adopted shard size is live (22.2 GB beside the miner, 13.2 seconds a shard, measured on the 32 GB card; a 24 GB card has not run it yet). The old 12 GB gate on the roadmap was withdrawn on 5 October until a prover build with a smaller floor was measured; on 6 October a patched server proved the same shard at 7.4 to 8.0 GB alone on eleven rented cards from the RTX 3060 to the RTX 5090 (the real-card table), so the gate returns as measured and the patched server is not yet in the shipped app. The first proofs exist: on 4 October 2026 an RTX 5090 proved a small two-transaction block in 1.4 seconds (2.7 seconds compressed), verified in 0.22 and 0.038 seconds, and a laptop CPU proved a three-shard block end to end in 19 minutes. Later that day the same card proved a full shard at the provisional size, 6.75 million prover gas, which executed in 60.8 million cycles: core proof 8.3 seconds, compressed proof 10.9 seconds, verified in 0.040 seconds; a four-shard block took 44.5 seconds of GPU stages end to end. Since 5 October 2026 shards are assigned and proven on the live devnet. The gate asks for a mid-range card, and an RTX 5090 is not one, so the gate stands open. Once the gate is measured, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface, so Igneum can adopt a better proof system when one exists by a miner-signalled release, and runs for ever on the current one if none is adopted.</p>
<h3>Proving for everyone else</h3>
<p>The same miners accept proving jobs from other chains. Rollups post a job, a miner wins it, proves it, and is paid. The job market is permissionless and is Designed, not yet built. At launch a job is paid on the customer's own chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum. Settlement in IGN, with 10% of each fee burned, follows when the proof bridge lets Igneum see the payment, in phase two. The Igneum miner client can also bid on other proving networks and take the best price, where a miner chooses to hold their collateral: Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation). The proving market is small today. Igneum does not depend on it. We know of no other proof-of-work chain selling proofs to other chains.</p>
</section>
@ -484,7 +484,7 @@ body.all .pager{display:none}
<ol>
<li><strong>Proofs at the cost of power.</strong> A contract requests a proof of any computation and the miners produce it. Their cards already run and are paid by emission, so a job only has to beat a few seconds of lottery income. Verification is folded into the chain's own proof; you ship no verifier. The price is a base fee that rises with the backlog, published at the phase 4 job market.</li>
<li><strong>Users who were not paid to arrive.</strong> Every miner is a funded wallet. Pools, payout contracts, hardware finance and hashrate forwards have customers before any consumer app does. Block rewards can pay straight to a contract.</li>
<li><strong>A share of fees, with the number stated.</strong> 20% of every priority fee goes to the contracts whose code ran, per call frame, to the payee registered at deployment. Libraries are paid at their code address. Factories pass their registration to what they deploy. At launch fee levels this is a property, not an income: a million calls a day at a 1 gwei tip pays about 7,300 IGN a year. It grows with traffic and nothing else.</li>
<li><strong>A share of fees, with the number stated.</strong> 20% of every priority fee goes to the contracts whose code ran, per call frame, to the payee registered at deployment. Libraries are paid at their code address. Factories pass their registration to what they deploy. At launch fee levels this is a property, not an income: a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year, with 1 gwei taken as a billionth of an IGN (the base unit is Open). It grows with traffic and nothing else.</li>
</ol>
<p>Ethereum stays your settlement. Move heavy compute to Igneum and return the result as a proof Ethereum verifies for about 250,000 gas. Igneum reads Ethereum's finality trustlessly from launch. Ethereum reads Igneum trustlessly in phase two. Until then, trust the bridge's operator.</p>
<p>No stablecoin and no official bridge at genesis. Grants come from founders' mined coins, for ports, audits and integrations, never for a user count. Execution is immediate, the miner lock lands in about two minutes; a withdrawal waits for the lock.</p>
@ -494,7 +494,7 @@ body.all .pager{display:none}
<h2>Economics</h2>
<p>The coin is IGN. It is gas and the proving currency, and part of every payment on Igneum is burned. Outside customers pay in their own currency on their own chain at launch; settlement in IGN with a 10% burn follows when the proof bridge lets Igneum see the payment, in phase two.</p>
<h3>Supply</h3>
<p>Fair launch. No premine, no pre-sale, no allocation to anyone. Hard cap of 4 billion IGN, approached and never reached, because emission starts at 1 billion a year and halves every two years for ever. Nearly a quarter of all supply is mined in the first year and half in the first two, so the people who show up early get the most. Emission ramps from 10% to 100% over the first 30 days so that nobody takes the first month before the rest of the world hears about it.</p>
<p>Fair launch. No premine, no pre-sale, no allocation to anyone. Hard cap of 4 billion IGN, approached and never reached, because emission starts at 1 billion a year and halves every two years for ever. Nearly a quarter of all supply is mined in the first year and half in the first two. Emission ramps from 10% to 100% over the first 30 days so that nobody takes the first month before the rest of the world hears about it.</p>
<div class="figure">
<svg viewBox="0 0 760 300" role="img" aria-label="Half of the 4 billion cap is mined in the first two years" font-family="IBM Plex Mono, monospace" font-size="12">
<text x="40" y="26" font-family="IBM Plex Sans, system-ui, sans-serif" font-size="15" font-weight="600" fill="var(--ink)">Half of the 4 billion cap is mined in the first two years</text>
@ -525,14 +525,28 @@ body.all .pager{display:none}
<thead><tr><th>Share</th><th>Goes to</th><th>Why</th></tr></thead>
<tbody>
<tr><td class="num">80%</td><td>The miner who wins the block</td><td>Pays the hashrate that secures the chain</td></tr>
<tr><td class="num">20%</td><td>The proving pool: shard provers and aggregators</td><td>Pays a standing prover population that does not have to hash</td></tr>
<tr><td class="num">20%</td><td>The proving pool: shard provers and aggregators</td><td>For a standing prover population that does not have to hash. On the devnet today the coinbase's 20% output goes to an unspendable script tagged <code>igneum-proving-pool-v0</code> and is burned there. Provers are paid from a separate escrow in the execution state, credited by rule with the same 20% of each blue block's subsidy and released per shard against valid proof records (Implemented, proving v0, since 5 October 2026). Open: the single coinbase payout that replaces the burn, and whether it reclaims the share burned so far</td></tr>
<tr><td class="num">0%</td><td>Treasury, foundation, team or stake</td><td>There is no coin-holder class in consensus and no tax on emission</td></tr>
</tbody>
</table></div>
<h3>Where fees go</h3>
<p>The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits two ways: 80% to the miner and provers of that block, 20% to the apps whose code ran, by gas consumed inside each. External proving fees, once they settle on Igneum, pay 90% to the provers who delivered and burn 10%. The hard cap fixes supply. Emission is untouched by any of this: every coin minted still goes to miners and provers.</p>
<h3>Every payment route</h3>
<p>One row per route, so operator income and protocol income never blur. The protocol pays no address of its own, and a burn pays nobody. Rows 1 to 5 are the protocol. Row 6 is the project's software, outside the protocol, and is never added to the other five.</p>
<div class="tbl"><table>
<thead><tr><th>Route</th><th>Currency</th><th>Recipient</th><th>Fee</th><th>Burn</th></tr></thead>
<tbody>
<tr><td>1. Emission, per block</td><td>IGN, new coins on the schedule above</td><td>80% the block's miner, 20% the proving pool for the provers of that block</td><td>None</td><td>None. Implemented in consensus: the 80/20 coinbase on the devnet</td></tr>
<tr><td>2. Base fee, both gas dimensions</td><td>IGN</td><td>Nobody</td><td>The base fee the chain sets per block</td><td>All of it. Implemented on the devnet</td></tr>
<tr><td>3. Priority fee</td><td>IGN</td><td>80% the block's miner and provers; 20% the apps whose code ran, per call frame</td><td>The tip the sender sets</td><td>The share of any frame in an unregistered contract. Implemented on the devnet</td></tr>
<tr><td>4. External job, at launch</td><td>The customer's currency, on the customer's chain</td><td>The miner who delivered, through a payout contract keyed by miner address</td><td>Priced in dollars per proof; the customer chain's own bond and slashing apply</td><td>None; Igneum cannot see the payment. Designed</td></tr>
<tr><td>5. External job, after the proof bridge</td><td>IGN, on Igneum</td><td>90% the provers who delivered</td><td>The job fee</td><td>10%. Designed, phase two</td></tr>
<tr><td>6. The official client's dev fee</td><td>IGN</td><td>The project, as operator income, never the protocol</td><td>1 block template in 100 requested with the dev address; off with one flag</td><td>None. Implemented, measured on a test network 4 October 2026</td></tr>
</tbody>
</table></div>
<p class="src"><b>Sources:</b> specification sections 2.5 and 5.1 to 5.4; the engineering log for the devnet receipts and the dev-fee count.</p>
<h3>Security after the subsidy</h3>
<p>The cap stays at 4 billion. There is no tail emission. Long term, security is paid for by the proving market and by fees. Outside customers buy proofs as dollars-priced work settled in IGN, and 90% of every job goes to the provers who delivered it, so a prover's income does not depend on emission. The table shows the first year in which the block subsidy on its own pays miners less than the power of about 3,000 consumer cards, at three flat prices. The prices are inputs chosen to span two orders of magnitude. The model runs a 300 W card at 124 MH/s on electricity at USD 0.12 per kWh. One rule sits beside the cap. If external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the question of a tail reward goes to the miners' signalling vote. The protocol never changes emission by itself.</p>
<p>The cap stays at 4 billion. There is no tail emission. The schedule is a bet, not a measurement: a halving halves emission income overnight if price and fees do nothing. Kaspa's steeper monthly reduction kept its hashrate while its price rose (approximate). Long term, security is paid for by the proving market and by fees. Outside customers buy proofs as dollars-priced work settled in IGN, and 90% of every job goes to the provers who delivered it, so a prover's income does not depend on emission. The table shows the first year in which the block subsidy on its own pays miners less than the power of about 3,000 consumer cards, at three flat prices. The prices are inputs chosen to span two orders of magnitude. The model runs a 300 W card at 124 MH/s on electricity at USD 0.12 per kWh. One rule sits beside the cap. If external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the question of a tail reward goes to the miners' signalling vote. The protocol never changes emission by itself.</p>
<div class="tbl"><table>
<thead><tr><th>Price per IGN</th><th>First year the subsidy alone pays under the power of 3,000 cards</th><th>Subsidy to miners that year</th></tr></thead>
<tbody>
@ -553,18 +567,18 @@ body.all .pager{display:none}
<thead><tr><th>Stream</th><th>Paid by</th><th>Moves with the IGN price?</th></tr></thead>
<tbody>
<tr><td>Block reward</td><td>Emission, 80% to the winner</td><td>Yes</td></tr>
<tr><td>In-chain proving</td><td>The 20% proving pool plus the proving share of every block's gas</td><td>Yes, mostly</td></tr>
<tr><td>In-chain proving</td><td>The 20% proving pool plus the proving share of every block's gas (on the devnet, paid from the execution-state escrow; see Economics)</td><td>Yes, mostly</td></tr>
<tr><td>External proving jobs</td><td>Rollups and apps on other chains, priced in their money</td><td>No, but the market is small today and is upside, not a promise</td></tr>
</tbody>
</table></div>
<p>The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' marginal cost in the proving market is close to power, which is an edge over data-centre provers and nothing more.</p>
<p>The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' marginal cost in the proving market is close to power, which is an edge over data-centre provers and nothing more. Which of the two in-chain streams pays more per GPU-second depends on the size of the fleet: on the devnet of 4 October 2026, three machines at 275 million hashes a second, a second of hashing paid about 4.9x a second of proving the pool share; at 10,000 cards the same arithmetic favours proving by about 930x. That is arithmetic on measured devnet rates, approximate, not a market measurement.</p>
<h3>Hardware</h3>
<p>The dataset starts at 2 GB and grows (the proposed schedule, fixed at the testnet genesis: 2 GB, doubling at years 4, 12 and 28, the average of half a gigabyte a year), so a 4 GB card mines for about four years and an 8 GB card for about twelve, approximate. 24 GB proves full shards (measured on a 32 GB card's allocation; a 24 GB card has not run it yet) and 32 GB mines and proves on one card, measured 5 October 2026 on this prover build (a 12 GB card does not prove on it: the GPU prover's floor is 13.9 GB). NVIDIA and AMD both work, because the mining program is generated for the architecture both share and the proof system is hash-based. Apple's chips are GPUs with unified memory, so Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second, an Apple M5 Max beside an RTX 5090 on the live devnet, 4 October 2026. A Mac is a poor miner per dollar. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.</p>
<p>The dataset starts at 2 GB and grows (the proposed schedule, fixed at the testnet genesis: 2 GB, doubling at years 4, 12 and 28, the average of half a gigabyte a year), so a 4 GB card mines for about four years and an 8 GB card for about twelve, approximate. Every NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server (eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026, <code>docs/analysis/prover-tiers-real-cards.md</code>). NVIDIA and AMD both work, because the mining program is generated for the architecture both share and the proof system is hash-based. Apple's chips are GPUs with unified memory, so Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second, an Apple M5 Max beside an RTX 5090 on the live devnet, 4 October 2026. A Mac is a poor miner per dollar. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.</p>
<h3>What a miner's hour looks like</h3>
<p>The card hashes the lottery continuously. When the client sees a shard or an external job it can win, it switches the card to proving for a few seconds, posts the proof, and goes back to hashing. The client does the switching and the miner sees one balance.</p>
<p>The protocol carries no fee: no dev fund, no cut to any team. Ember, the miner software, takes an optional 1% dev fee, the way other GPU miners do. One block template in 100 is requested with the dev address instead of yours, by a counter, not a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. One flag turns it off (<code>--dev-fee 0</code>, a switch in the app, a line in the HiveOS config). The miner prints the fee and the address when it starts. Any other client is welcome.</p>
<h3>One click, for everyone else</h3>
<p>Farm operators get a HiveOS package. Everyone else gets Igneum Ember: install it on Windows, macOS or Linux, press one button, and the card is mining and proving to a key the app made for you, with earnings shown in IGN and in your currency, and mining paused while you game. It is the same client with a face on it. The app shows you the key and has you save it before mining starts, offers a hardware wallet for your earnings, updates itself from releases signed by the project's release key with a switch to turn that off, and is downloaded only from this domain or the repository with its hash shown beside the button. The next section says what is shipped and what is still a design. Nobody from Igneum will ever ask for your seed. Mining never runs in a browser, because browser compute is slow and browser mining has meant malware since Coinhive. The browser is for the dashboard, and for verifying the chain.</p>
<p>Farm operators get a HiveOS package. Everyone else gets Igneum Ember: install it on Windows, macOS or Linux, press Start, and the card is mining to a key the app made for you. It is the same client with a face on it. Implemented, Ember 0.3.9 (5 October 2026): the app shows the key once and has you save it before mining starts, or takes an address you already have; the dashboard shows each card's hash rate, blocks found and accepted by the node, the node's height and peers, the next hourly program, the finality votes sent, and a proving tile with shards assigned, submitted and paid and the verifier state; the chain label reads devnet v4 and the welcome screen says nothing is bought or sold; NVIDIA cards are capped at 80% of their default power limit for stability, with a sweep that looks for the best hash per watt, not yet measured on a card; proving the shards the chain assigns is a switch in Settings (proving v0), beside the 1% dev fee switch, finality voting, and signed updates that install themselves at a quiet moment with a switch to turn that off. It shows no earnings in IGN or in any currency, and it has no hardware-wallet path. Roadmap, Designed and not in the app: earnings per block in IGN with the network named, a figure in your currency, mining paused while you game, and a hardware wallet for your key. Ember is downloaded only from this domain, with the version and size on the button and the hash in the signed manifest the app checks. The next section says what is shipped and what is still a design. Nobody from Igneum will ever ask for your seed. Mining never runs in a browser, because browser compute is slow and browser mining has meant malware since Coinhive. The browser is for the dashboard, and for verifying the chain.</p>
<h3>Fair launch, announced</h3>
<p>Launch date and miner software published a month ahead. Pools live on testnet. HiveOS support on day one. The founders mine from genesis like everyone else, with disclosed addresses and the same software. Nobody has coins before block one. The first 30 days of mainnet run on proof of work alone, with no locked checkpoint, while vote weights build; anyone crediting deposits in that month should treat Igneum as plain proof of work with a 12-hour depth.</p>
</section>
@ -642,7 +656,7 @@ body.all .pager{display:none}
<li><strong>Nothing needs a scheduled upgrade.</strong> The mining program, the dataset and the finality rules run themselves for ever. If the community ever ships an improvement, a better proof system or a block-rate step, it is published with test vectors at least three months ahead and activates only when 90% of blocks signal readiness. Developers can write code. Only miners can turn it on.</li>
<li><strong>Miners set what genesis leaves open.</strong> A parameter that the genesis rules leave to miners is set by signalling: a proposal passes or fails on 60% of hashrate over two weeks. There is no fund to vote on and no fee to any team, foundation or fund.</li>
<li><strong>Pools can be bypassed on transaction choice.</strong> Igneum ships Stratum v2 job declaration from day one, so a miner chooses its own transactions when its pool supports it. Pools can decline, and vote keys stay with the pool. Designed: the pool protocol is specification section 9, not yet run by any pool.</li>
<li><strong>There are no admin keys in consensus.</strong> Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy. The genesis apps are contracts, and each publishes its own upgrade and key policy before launch; the bridge's is the one to read. Designed, open item O-5.4.</li>
<li><strong>There are no admin keys in consensus.</strong> Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy. The genesis apps are contracts, and each publishes its own upgrade and key policy before launch; the bridge's is the one to read. Designed, open item O-5.4. On the devnet the activation heights and one execution-state restart (6 October 2026) reach every node through the signed update manifest, so on the devnet the release key acts as the operator; the sentence above holds for mainnet consensus only once that path is closed, and the public testnet terms will say which parameters still travel that way.</li>
<li><strong>The chain runs without its founders.</strong> Blocks, proofs and finality need no one. A second independent node client is the first priority after launch, and anyone can build it.</li>
</ul>
</section>
@ -681,9 +695,23 @@ body.all .pager{display:none}
<section id="miners-ask">
<h2>Questions miners ask</h2>
<h3>Kaspa was GPU-mined too, and IceRiver shipped a chip within two years.</h3>
<p>Kaspa never promised chip resistance, and its hash was one fixed function, simple enough to put on silicon. Igneum's program is different every hour, its dataset grows past any fixed memory, and its program space widens every era, with no human involved. The benchmark tool ships in January 2027, and its source is public with the repository at the public testnet, so you run it on your own card and post the number to a leaderboard by card model. A standing bounty pays anyone who can show a chip design that beats a GPU by more than 2x. And if a chip ever appears, miners are the ones who signal the response.</p>
<p>Kaspa never promised chip resistance, and its hash was one fixed function, simple enough to put on silicon. Igneum's program is different every hour, its dataset grows past any fixed memory, and its program space widens every era, with no human involved. The benchmark tool ships in January 2027, and its source is public with the repository at the public testnet, so you run it on your own card and post the number to a leaderboard by card model. The paid independent cryptanalysis and the public benchmark are where a chip design that beats a GPU by more than 2x would show. And if a chip ever appears, miners are the ones who signal the response.</p>
<h3>Don't ASICs make a chain safer?</h3>
<p>Three parts. First, what the chain asks hash to do. Hash picks who makes the next block. It does not protect history. A checkpoint locks when signatures reach two thirds of the weight of the last 30 days of blocks (specification section 3). A locked checkpoint is never reorganised by any amount of hash: fork choice runs among the tips that pass through every certified checkpoint. Rented hash has no weight today. It can mine blocks. It cannot rewrite anything older than a lock. A renter with 60% of the network holds 0.0% of the vote on day one (the finality simulator, table B); one matching the whole honest network reaches a third of the weight on day 20 and never two thirds. The lock is fast: median 1,018 ms behind the checkpoint on the three-node test network (engineering log, the finality harness), and on the live devnet the first lock came two hours after genesis, once the window was full. Reorganisations under the lock are shallow: at 1, 2 and 5 blocks a second the deepest honest reorganisation measured was 2, 3 and 7 blocks against a determination depth of 20 (ledger F7, round 2, the fast-time network with 100-ms links); across five continents blocks reached every node at p50 343 ms and p99 666 ms (the 12-node cloud network, 4 October 2026).</p>
<p>Second, the cost the ASIC argument skips. Kaspa's hash went to a handful of chip owners within months: the IceRiver KS0 shipped in July 2023, 17 to 20 months after launch; hashrate went from under 100 PH/s to over 700 PH/s in months and the GPU share was negligible by late 2023 (the ASIC history, row 23, approximate for the share). Bitcoin's hash comes from two manufacturers and a few pools (approximate, from memory). The first chip's owner mines in secret with an edge for months: on Monero, 85% of the hashrate vanished at the April 2018 fork, and chips were found at over 85% again four months after the next fork (row 16). A chip does not add security to a chain; it moves the chain's security to whoever owns the chip first.</p>
<p>Third, the honest part. A young GPU chain's hash is cheap to rent, and we publish the number beside the chain's own. The locks are what make that rental unable to buy a double-spend: a deposit under a lock stays, whatever the renter mines on top. Ethereum Classic (January 2019 and August 2020), Bitcoin Gold (May 2018 and January 2020) and Vertcoin (October to December 2018, December 2019) were reorganised with rented hash (the ASIC history rows 6 and 7 for Bitcoin Gold and Vertcoin; the Ethereum Classic dates approximate, from memory); Verge's 2018 reorganisations used a timestamp flaw in its multi-algorithm rule as well as hash (approximate). On those chains the rented hash rewrote history because nothing but hash held it. Here the same rental mines blocks for its hour and leaves the locks where they were. The exception is stated above: in the first 30 days of mainnet no checkpoint locks, the chain is plain proof of work with a 12-hour depth, and a rental can reorganise inside that depth; anyone crediting deposits in that month treats it so.</p>
<div class="tbl"><table>
<thead><tr><th>What</th><th>Number</th><th>Source</th></tr></thead>
<tbody>
<tr><td>Rented NVIDIA hash, 6 October 2026</td><td class="num">2 GH/s for USD 13 an hour</td><td>The fleet's bench entry (the rented cards of 6 October 2026); the entry lands tonight with the wave measurement below</td></tr>
<tr><td>The devnet's hash the same afternoon</td><td class="num">282 MH/s</td><td><code>/api/stats</code>, 6 October 2026, 16:40 UTC; 181 MH/s an hour earlier with one PC off</td></tr>
<tr><td>Weight a renter holds on day one</td><td class="num">0.0%</td><td>The finality simulator, table B (ledger M12)</td></tr>
<tr><td>Lock latency behind the checkpoint</td><td class="num">1,018 ms median</td><td>Engineering log, the finality harness, three nodes</td></tr>
<tr><td>A 50-miner wave against the devnet: blocks taken, locks moved</td><td class="num">measurement tonight</td><td>The fleet's bench entry, 6 October 2026</td></tr>
</tbody>
</table></div>
<h3>Finality weighted by mining history is new. New gets attacked.</h3>
<p>Correct, and it is the first thing the external review will be paid to break. The specification is public; reviewers will be named and paid before gate 3, and a bounty is attached. Until then every finality claim here is a design claim backed by simulations and by the devnet, and the chain runs on plain GHOSTDAG without the rule, so it can be fixed without stopping the chain.</p>
<p>Correct, and it is the first thing the external review will be paid to break. The specification is public; reviewers will be named and paid before gate 3, and the public benchmark carries the metrics they test against. Until then every finality claim here is a design claim backed by simulations and by the devnet, and the chain runs on plain GHOSTDAG without the rule, so it can be fixed without stopping the chain.</p>
<h3>Who are you?</h3>
<p>One founder, pseudonymous, working with AI systems. The design, the hostile reviews, the code, the simulators and this document were produced that way, and the commit history says so. The software is shipped by Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre. The design remains the work of one founder working with AI systems, reviewed in public through the ledger. What that does and does not mean: the measurements are measurements, reproducible from the commands in the engineering log; the simulators are code anyone can run; the design claims stay design claims until people with names have tried to break them. Every criticism the project expects is kept in a ledger with its honest answer, and the entries that were right are marked conceded; the ledger is published with the repository at the public testnet. No cryptographer is hired yet; the plan budgets one for phases 1 and 2, and external reviewers are named and paid before gate 3.</p>
<p>The founders mine from genesis with disclosed addresses and the same software as everyone else, and hold no coins before block one. The team is pseudonymous and there is no team page. The mining addresses and the code history are published with the repository at the public testnet.</p>
@ -700,7 +728,7 @@ body.all .pager{display:none}
<h3>What does a one-minute proof mean for my app?</h3>
<p>Nothing you wait for. Your transaction executes in about a second. A miner lock arrives in about two minutes and that is the finality your contract sees. The proof follows and makes the state unforgeable. Liquidations and trades act on executed state at once, as on any chain. A bridge built on Igneum waits for the lock, about two minutes.</p>
<h3>Which stablecoin, and is there liquidity?</h3>
<p>None is bridged at genesis, and no bridge is official. Native USDC is requested from Circle during testnet, and anyone may run a bridge at their own risk until the proof bridge arrives with the consensus proof in phase two. The DEX is seeded at launch by the founders' own mined coins and by miners, and every miner is a funded wallet.</p>
<p>None is bridged at genesis, and no bridge is official. The project will ask Circle for native USDC during the public testnet; whether it is issued is Circle's decision. Anyone may run a bridge at their own risk until the proof bridge arrives with the consensus proof in phase two. The DEX is seeded at launch by the founders' own mined coins and by miners, and every miner is a funded wallet.</p>
<h3>What do I get for being early?</h3>
<p>20% of the priority fee on every transaction that runs your code, paid to you every block, which at launch fee levels is small and stated as such above. A place in the wallet's Apps tab and the explorer from day one. First access to the proving precompile and the job market. And a user base that was not paid to arrive: the miners.</p>
<h3>How do I deploy?</h3>
@ -730,7 +758,7 @@ body.all .pager{display:none}
<p>Here are the limits, stated before anyone else states them.</p>
<ul>
<li><strong>A proof in seconds.</strong> Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.</li>
<li><strong>A chip is impossible.</strong> No. A chip is a bad bet, because the target moves before it ships. The published model (5 October 2026) prices the strongest chip we can name, one with the whole cache on-die computing dataset items on the fly, at 0.92x the hash rate of an RTX 5090 per unit of silicon with a 3x fixed-function allowance, approximate; the claim is under 2x, the margin is stated on the numbers page, and the next lever is named there. No hash has stayed free of chips forever; Igneum does not claim to. Monero's seven years without a public chip are precedent, not proof.</li>
<li><strong>A chip is impossible.</strong> No. A chip is a bad bet, because the target moves before it ships. The published model (5 October 2026) prices the strongest chip we can name, one with the whole cache on-die computing dataset items on the fly, at 0.92x the hash rate of an RTX 5090 per unit of silicon with a 3x fixed-function allowance, approximate. The same model, drawn out to the chip that stores the dataset (6 October 2026): The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090. A memory-controller chip that stores the whole dataset reaches 1.2x per chip and, in our model, 5x to 9x per joule; the Ethash chips of this class reached 2.1x to 4.8x. The lever against it, program work in the latency shadow, is measured and in its gates: it brings the chip to about 2x. Sources: the chip model (<code>docs/analysis/chip-model-v3.md</code> section 5, 6 October 2026); the Ethash rows of the ASIC history (<code>docs/analysis/asic-resistance-history.md</code>, Linzhi Phoenix 2020, Jasminer X4 2021, Antminer E9 2022); Counter ASIC 3.0 item 8 (100,000 ops per hash: the chip's per-joule edge over the RTX 5090 falls from 5.6x to 2.1x on GDDR7 at a chip core equal to the GPU's, the 5090 at 0.2% less rate, gates G1 to G6 in progress). No hash has stayed free of chips forever; Igneum does not claim to. Monero's seven years without a public chip are precedent, not proof, and a small prize: they say nothing about the price of a chip with the 256 MB cache on its die, and that price is a cost model, not a measurement.</li>
<li><strong>A guaranteed income floor.</strong> No. External proving is a small market today. Igneum's miners' marginal cost in it is close to power, which is an edge and nothing more.</li>
<li><strong>A memory-hard prototype on every vendor.</strong> Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.</li>
<li><strong>Finality in the first month.</strong> No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.</li>
@ -761,6 +789,7 @@ body.all .pager{display:none}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -286,6 +286,7 @@ main{padding-bottom:var(--sec)}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -248,6 +248,7 @@ pre{margin:0 0 16px;padding:16px 18px;background:var(--graphite);border-radius:v
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -4,13 +4,13 @@
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
<title>The Igneum miner app</title>
<meta name="description" content="One click: install, start, the card mines, and an NVIDIA card with 24 GB proves. Auto GPU detection on NVIDIA, AMD and Apple silicon, a wallet made for you, hourly program swaps with no pause, signed updates, a visible 1% software fee you can switch off.">
<meta name="description" content="One click: install, start, the card mines, and every NVIDIA card from 8 GB proves. Auto GPU detection on NVIDIA, AMD and Apple silicon, a wallet made for you, hourly program swaps with no pause, signed updates, a visible 1% software fee you can switch off.">
<link rel="canonical" href="https://igneum.network/miner">
<meta name="theme-color" content="#0C0C0E">
<meta property="og:type" content="website">
<meta property="og:site_name" content="Igneum">
<meta property="og:title" content="The Igneum miner app">
<meta property="og:description" content="One click: install, start, the card mines, and an NVIDIA card with 24 GB proves. Auto GPU detection on NVIDIA, AMD and Apple silicon, a wallet made for you, hourly program swaps with no pause, signed updates, a visible 1% software fee you can switch off.">
<meta property="og:description" content="One click: install, start, the card mines, and every NVIDIA card from 8 GB proves. Auto GPU detection on NVIDIA, AMD and Apple silicon, a wallet made for you, hourly program swaps with no pause, signed updates, a visible 1% software fee you can switch off.">
<meta property="og:url" content="https://igneum.network/miner">
<meta property="og:image" content="https://igneum.network/og.png?v=3">
<meta property="og:image:width" content="1200">
@ -18,7 +18,7 @@
<meta property="og:image:alt" content="Igneum. Mined by GPUs. Proven by fire.">
<meta name="twitter:card" content="summary_large_image">
<meta name="twitter:title" content="The Igneum miner app">
<meta name="twitter:description" content="One click: install, start, the card mines, and an NVIDIA card with 24 GB proves. Auto GPU detection, a wallet made for you, hourly program swaps with no pause, signed updates, a visible 1% software fee you can switch off.">
<meta name="twitter:description" content="One click: install, start, the card mines, and every NVIDIA card from 8 GB proves. Auto GPU detection, a wallet made for you, hourly program swaps with no pause, signed updates, a visible 1% software fee you can switch off.">
<meta name="twitter:image" content="https://igneum.network/og.png?v=3">
<meta name="twitter:image:alt" content="Igneum. Mined by GPUs. Proven by fire.">
<link rel="icon" href="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 1024 1024'%3E%3Crect width='1024' height='1024' fill='%230C0C0E'/%3E%3Cg transform='translate(166.95 166.95) scale(6.901)'%3E%3Cpolygon points='50,4 74,34 67,58 80,54 61,96 39,96 20,54 33,58 26,34' fill='%23F2541B'/%3E%3Cpolygon points='50,42 59,58 50,82 41,58' fill='%230C0C0E'/%3E%3C/g%3E%3C/svg%3E" type="image/svg+xml">
@ -249,7 +249,7 @@ pre b{color:var(--molten);font-weight:500}
<div class="wrap">
<div class="hero-copy">
<div class="eyebrow ember"><span data-product="full">Igneum Ember</span> · one click</div>
<h1>Install. Start. The card mines. An NVIDIA card with 24 GB proves too.</h1>
<h1>Install. Start. The card mines. Every NVIDIA card from 8 GB proves; 12 GB and up mine and prove.</h1>
<p class="lead"><span data-product="name">Ember</span> finds your GPU, makes a wallet for you and runs the node, the miner and the prover as one app. Every hour it compiles the next program while the current one mines, so the card never stops.</p>
<div class="cta">
<a href="#get" class="btn primary">Downloads: public testnet</a>
@ -305,7 +305,7 @@ pre b{color:var(--molten);font-weight:500}
<div class="group reveal" id="start">
<div class="g-head"><div class="eyebrow ember">01 · One click</div><h3>Install, press Start</h3><p>Five steps from download to the first block on a friend's laptop: drag to Applications, open, Get started, Make me an address, Start mining.</p></div>
<div class="feats">
<div class="feat"><b>The card mines; an NVIDIA card proves</b><p>One button starts the node, waits for sync, starts one miner per card and, on an NVIDIA card with 24 GB or more, the prover. AMD and Apple cards mine; a prover for them lands when a zkVM ships one. Quit stops them in order.</p></div>
<div class="feat"><b>The card mines; an NVIDIA card proves</b><p>One button starts the node, waits for sync, starts one miner per card and, on an NVIDIA card, the prover: every NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server (eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026, docs/analysis/prover-tiers-real-cards.md); the patched server for the smaller cards is not yet in the shipped app. AMD and Apple cards mine; a prover for them lands when a zkVM ships one. Quit stops them in order.</p></div>
<div class="feat"><b>Finds your GPU by itself</b><p>NVIDIA through the driver, AMD and Intel through OpenCL, Apple silicon through Metal. Real card names, one worker per card.</p></div>
<div class="feat"><b>A wallet made for you</b><p>A payout key made on your machine and locked to your user, with a backup step before mining starts. Or paste an address you already hold.</p></div>
<div class="feat"><b>Earnings in IGN</b><p>Every block this machine finds pays one address in IGN. The dashboard counts them per run, per hour and for life. The <a href="/wallet" style="color:var(--ember)">wallet</a> shows the balance.</p></div>
@ -456,18 +456,19 @@ pre b{color:var(--molten);font-weight:500}
<h2>Get the miner</h2>
<p>Download only from this domain. Nobody from Igneum will ask for your seed. Every file below is the one the app's signed manifest names, with its version and size.</p>
<p data-testnet-notice style="margin-top:10px;font-weight:600;color:var(--molten)">Public testnet: not yet open; the devnet build is here for people who want to look.</p>
<p data-devnet-notice style="margin-top:6px;font-weight:600;color:var(--molten)">Devnet: coins have no value and the chain may be reset.</p>
</div>
<div class="cta reveal" style="align-items:center">
<a data-dl="miner-windows" href="https://dl.igneum.network/public/igneum-miner-windows.exe" class="btn primary"><svg viewBox="0 0 24 24" width="18" height="18" fill="currentColor" aria-hidden="true"><path d="M3 5.5l7.5-1v7H3zM11.5 4.3L21 3v8.5h-9.5zM3 12.5h7.5v7L3 18.5zM11.5 12.5H21V21l-9.5-1.3z"/></svg>Windows <span data-dl-meta="miner-windows" style="font-weight:400;opacity:.85">v0.3.10 · 49.9 MB</span></a>
<a data-dl="miner-mac" href="https://dl.igneum.network/public/igneum-miner-mac.dmg" class="btn primary"><svg viewBox="0 0 24 24" width="18" height="18" fill="currentColor" aria-hidden="true"><path d="M16.4 12.6c0-2.3 1.9-3.4 2-3.5-1.1-1.6-2.8-1.8-3.4-1.8-1.4-.1-2.8.8-3.5.8-.7 0-1.8-.8-3-.8-1.5 0-3 .9-3.8 2.3-1.6 2.8-.4 7 1.2 9.3.8 1.1 1.7 2.4 2.9 2.3 1.2 0 1.6-.7 3-.7s1.8.7 3 .7c1.3 0 2-1.1 2.8-2.3.9-1.3 1.2-2.6 1.3-2.6-.1 0-2.5-.9-2.5-3.7zM14.1 5.8c.6-.8 1.1-1.9.9-3-.9 0-2 .6-2.7 1.4-.6.7-1.1 1.8-1 2.9 1.1.1 2.1-.5 2.8-1.3z"/></svg>macOS <span data-dl-meta="miner-mac" style="font-weight:400;opacity:.85">v0.3.10 · 41.4 MB</span></a>
<a data-dl="miner-hive" href="https://dl.igneum.network/public/igneum-miner-hive.tar.gz" class="btn"><svg viewBox="0 0 24 24" width="18" height="18" fill="currentColor" aria-hidden="true"><path d="M12 2c-2.4 0-4 1.9-4 4.6 0 1.2.2 2 0 2.8-.6 1.4-2.1 2.9-2.6 4.9-.3 1.1-.1 2 .3 2.6-.6.4-1.3 1-1.1 1.7.3 1 2.1 1.2 3.2 1.8.7.4 1.5.6 2.1.1.6.2 1.3.3 2.1.3s1.5-.1 2.1-.3c.6.5 1.4.3 2.1-.1 1.1-.6 2.9-.8 3.2-1.8.2-.7-.5-1.3-1.1-1.7.4-.6.6-1.5.3-2.6-.5-2-2-3.5-2.6-4.9-.2-.8 0-1.6 0-2.8C16 3.9 14.4 2 12 2zm-1.4 4.2c.5 0 .8.5.8 1.2s-.3 1.2-.8 1.2-.8-.5-.8-1.2.3-1.2.8-1.2zm2.8 0c.5 0 .8.5.8 1.2s-.3 1.2-.8 1.2-.8-.5-.8-1.2.3-1.2.8-1.2zM12 9.3c.9 0 1.9.5 1.9 1s-1 1.2-1.9 1.2-1.9-.7-1.9-1.2 1-1 1.9-1zm0 3.4c2.2 0 3.6 2.6 3.6 4.4 0 1.5-1.6 2.3-3.6 2.3s-3.6-.8-3.6-2.3c0-1.8 1.4-4.4 3.6-4.4z"/></svg>Linux <span data-dl-meta="miner-hive" style="font-weight:400;opacity:.85">v0.3.9 · 24.2 MB</span></a>
<a data-dl="miner-hive" href="https://dl.igneum.network/public/igneum-miner-hive.tar.gz" class="btn"><svg viewBox="0 0 24 24" width="18" height="18" fill="none" stroke="currentColor" stroke-width="2" stroke-linejoin="round" aria-hidden="true"><path d="M12 2.5l8.2 4.75v9.5L12 21.5l-8.2-4.75v-9.5z"/><path d="M12 7.5l4.3 2.5v5L12 17.5l-4.3-2.5v-5z"/></svg>HiveOS <span data-dl-meta="miner-hive" style="font-weight:400;opacity:.85">v0.3.9 · 24.2 MB</span></a>
<a data-dl="miner-windows" href="https://dl.igneum.network/public/igneum-miner-windows.exe" class="btn primary"><svg viewBox="0 0 24 24" width="18" height="18" fill="currentColor" aria-hidden="true"><path d="M3 5.5l7.5-1v7H3zM11.5 4.3L21 3v8.5h-9.5zM3 12.5h7.5v7L3 18.5zM11.5 12.5H21V21l-9.5-1.3z"/></svg>Windows <span data-dl-meta="miner-windows" style="font-weight:400;opacity:.85">v0.3.13 · 45.4 MB</span></a>
<a data-dl="miner-mac" href="https://dl.igneum.network/public/igneum-miner-mac.dmg" class="btn primary"><svg viewBox="0 0 24 24" width="18" height="18" fill="currentColor" aria-hidden="true"><path d="M16.4 12.6c0-2.3 1.9-3.4 2-3.5-1.1-1.6-2.8-1.8-3.4-1.8-1.4-.1-2.8.8-3.5.8-.7 0-1.8-.8-3-.8-1.5 0-3 .9-3.8 2.3-1.6 2.8-.4 7 1.2 9.3.8 1.1 1.7 2.4 2.9 2.3 1.2 0 1.6-.7 3-.7s1.8.7 3 .7c1.3 0 2-1.1 2.8-2.3.9-1.3 1.2-2.6 1.3-2.6-.1 0-2.5-.9-2.5-3.7zM14.1 5.8c.6-.8 1.1-1.9.9-3-.9 0-2 .6-2.7 1.4-.6.7-1.1 1.8-1 2.9 1.1.1 2.1-.5 2.8-1.3z"/></svg>macOS <span data-dl-meta="miner-mac" style="font-weight:400;opacity:.85">v0.3.13 · 41.9 MB</span></a>
<a data-dl="miner-hive" href="https://dl.igneum.network/public/igneum-miner-hive.tar.gz" class="btn"><svg viewBox="0 0 24 24" width="18" height="18" fill="currentColor" aria-hidden="true"><path d="M12 2c-2.4 0-4 1.9-4 4.6 0 1.2.2 2 0 2.8-.6 1.4-2.1 2.9-2.6 4.9-.3 1.1-.1 2 .3 2.6-.6.4-1.3 1-1.1 1.7.3 1 2.1 1.2 3.2 1.8.7.4 1.5.6 2.1.1.6.2 1.3.3 2.1.3s1.5-.1 2.1-.3c.6.5 1.4.3 2.1-.1 1.1-.6 2.9-.8 3.2-1.8.2-.7-.5-1.3-1.1-1.7.4-.6.6-1.5.3-2.6-.5-2-2-3.5-2.6-4.9-.2-.8 0-1.6 0-2.8C16 3.9 14.4 2 12 2zm-1.4 4.2c.5 0 .8.5.8 1.2s-.3 1.2-.8 1.2-.8-.5-.8-1.2.3-1.2.8-1.2zm2.8 0c.5 0 .8.5.8 1.2s-.3 1.2-.8 1.2-.8-.5-.8-1.2.3-1.2.8-1.2zM12 9.3c.9 0 1.9.5 1.9 1s-1 1.2-1.9 1.2-1.9-.7-1.9-1.2 1-1 1.9-1zm0 3.4c2.2 0 3.6 2.6 3.6 4.4 0 1.5-1.6 2.3-3.6 2.3s-3.6-.8-3.6-2.3c0-1.8 1.4-4.4 3.6-4.4z"/></svg>Linux <span data-dl-meta="miner-hive" style="font-weight:400;opacity:.85">v0.3.13 · 24.6 MB</span></a>
<a data-dl="miner-hive" href="https://dl.igneum.network/public/igneum-miner-hive.tar.gz" class="btn"><svg viewBox="0 0 24 24" width="18" height="18" fill="none" stroke="currentColor" stroke-width="2" stroke-linejoin="round" aria-hidden="true"><path d="M12 2.5l8.2 4.75v9.5L12 21.5l-8.2-4.75v-9.5z"/><path d="M12 7.5l4.3 2.5v5L12 17.5l-4.3-2.5v-5z"/></svg>HiveOS <span data-dl-meta="miner-hive" style="font-weight:400;opacity:.85">v0.3.13 · 24.6 MB</span></a>
</div>
<div class="card reveal" id="hive" style="margin-top:28px;overflow-wrap:anywhere;word-break:break-word;min-width:0">
<div class="eyebrow">HiveOS · Flight Sheet</div>
<h3 style="margin:8px 0 10px">Install on a Hive rig</h3>
<p style="font-size:15px;color:var(--ink-2)">Miner: <b>Custom</b>. Installation URL: <code data-dl-url="miner-hive">https://dl.igneum.network/dl/public/igneum-hive-0.3.9.tar.gz</code>. Miner name <code>igneum</code>, wallet and worker <code>0x&lt;your 40-hex payout address&gt;.%WORKER_NAME%</code>, pool URL <code>grpc://&lt;your node&gt;:26610</code> or <code>local</code> for the bundled node, extra config <code>DEV_FEE=1 IDENTITIES=8 WORKER=auto VOTE=1</code>. The Linux button above is the same archive: the Linux miner, node and both GPU workers. Hive itself is untested so far. Report what breaks.</p>
<p style="font-size:13px;color:var(--ash);margin-top:8px;overflow-wrap:anywhere">sha256 <span class="mono" data-dl-sha="miner-hive" style="word-break:break-all">7a58a30fd47c9ecb3d4aeaa0c0a464550f7e4b2b33eacf87512f1b72164c829e</span></p>
<p style="font-size:15px;color:var(--ink-2)">Miner: <b>Custom</b>. Installation URL: <code data-dl-url="miner-hive">https://dl.igneum.network/dl/public/igneum-hive-0.3.13.tar.gz</code>. Miner name <code>igneum</code>, wallet and worker <code>0x&lt;your 40-hex payout address&gt;.%WORKER_NAME%</code>, pool URL <code>grpc://&lt;your node&gt;:26610</code> or <code>local</code> for the bundled node, extra config <code>DEV_FEE=1 IDENTITIES=8 WORKER=auto VOTE=1</code>. The Linux button above is the same archive: the Linux miner, node and both GPU workers. Hive itself is untested so far. Report what breaks.</p>
<p style="font-size:13px;color:var(--ash);margin-top:8px;overflow-wrap:anywhere">sha256 <span class="mono" data-dl-sha="miner-hive" style="word-break:break-all">65ea42600236c7024844d85fc401ef2c4650e671d92061c8db6415038bac9530</span></p>
</div>
<p class="pt reveal" style="margin-top:20px">Testnet coin for testing: <a href="/faucet" style="color:var(--ember)">the faucet</a> sends 10 IGN per address per day. Any 4 GB card at launch. The dataset starts at 2 GB and grows (the proposed schedule, fixed at the testnet genesis: 2 GB, doubling at years 4, 12 and 28), so a 4 GB card mines for about four years, approximate. Updates arrive signed; the app installs them itself. The <a href="/wallet" style="color:var(--ember)">wallet</a> reads this machine's node when the miner is installed.</p>
<a href="/litepaper#miners" class="lp reveal">Read more in the litepaper</a>
@ -501,6 +502,7 @@ pre b{color:var(--molten);font-weight:500}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -209,6 +209,7 @@ th{font-family:var(--f-mono);font-size:12px;letter-spacing:.12em;text-transform:
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -13,6 +13,7 @@
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

View file

@ -1,7 +1,7 @@
{
"cleanUrls": true,
"trailingSlash": false,
"redirects": [{"source": "/ledger", "destination": "/", "permanent": false}],
"redirects": [],
"rewrites": [{"source": "/block/:id", "destination": "/block"}, {"source": "/address/:addr", "destination": "/address"}],
"headers": [
{"source": "/(.*)", "headers": [{"key": "X-Content-Type-Options", "value": "nosniff"}, {"key": "X-Frame-Options", "value": "DENY"}, {"key": "Referrer-Policy", "value": "strict-origin-when-cross-origin"}, {"key": "Strict-Transport-Security", "value": "max-age=63072000; includeSubDomains; preload"}]},

View file

@ -365,6 +365,7 @@ td.num{font-variant-numeric:tabular-nums;white-space:nowrap}
<h2>Get the wallet</h2>
<p>Download only from this domain. Nobody from Igneum will ask for your seed. The file below is the one the wallet's signed manifest names, with its version and size.</p>
<p data-testnet-notice style="margin-top:10px;font-weight:600;color:var(--molten)">Public testnet: not yet open; the devnet build is here for people who want to look.</p>
<p data-devnet-notice style="margin-top:6px;font-weight:600;color:var(--molten)">Devnet: coins have no value and the chain may be reset.</p>
</div>
<div class="cta reveal" style="align-items:center">
<a data-dl="wallet-mac" href="https://dl.igneum.network/public/igneum-wallet-mac.dmg" class="btn primary"><svg viewBox="0 0 24 24" width="18" height="18" fill="currentColor" aria-hidden="true"><path d="M16.4 12.6c0-2.3 1.9-3.4 2-3.5-1.1-1.6-2.8-1.8-3.4-1.8-1.4-.1-2.8.8-3.5.8-.7 0-1.8-.8-3-.8-1.5 0-3 .9-3.8 2.3-1.6 2.8-.4 7 1.2 9.3.8 1.1 1.7 2.4 2.9 2.3 1.2 0 1.6-.7 3-.7s1.8.7 3 .7c1.3 0 2-1.1 2.8-2.3.9-1.3 1.2-2.6 1.3-2.6-.1 0-2.5-.9-2.5-3.7zM14.1 5.8c.6-.8 1.1-1.9.9-3-.9 0-2 .6-2.7 1.4-.6.7-1.1 1.8-1 2.9 1.1.1 2.1-.5 2.8-1.3z"/></svg>macOS <span data-dl-meta="wallet-mac" style="font-weight:400;opacity:.85">v0.1.4 · 19.6 MB</span></a>
@ -403,6 +404,7 @@ td.num{font-variant-numeric:tabular-nums;white-space:nowrap}
<a href="/litepaper#shoulders">Built on the shoulders</a>
<a href="/bench">Engineering log</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
</nav>
<nav class="foot-col" aria-label="Run">
<div class="eyebrow">Run</div>

213
tools/ledger-page.mjs Normal file
View file

@ -0,0 +1,213 @@
#!/usr/bin/env node
// Renders docs/fud-ledger.md as the public page site/ledger.html: every entry, the critic's words, what was done, the
// status and the date, with the count table on top. Nothing is dropped and nothing is softened; the only rewrites are
// the identity and provider terms of site/forbidden-strings.txt (the tree's public-export rule), applied in place.
// Usage: node tools/ledger-page.mjs [docs/fud-ledger.md] [site/ledger.html]
import { readFileSync, writeFileSync } from 'node:fs';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
const here = dirname(fileURLToPath(import.meta.url));
const root = join(here, '..');
const src = process.argv[2] || join(root, 'docs', 'fud-ledger.md');
const out = process.argv[3] || join(root, 'site', 'ledger.html');
const esc = s => s.replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;');
// Identity and provider terms. The criticism keeps its force; the operational name goes.
const SCRUB = [
[/\bJosh's\b/g, "the owner's"], [/\bJosh\b/g, 'the owner'],
[/\bHetzner\b/g, 'the cloud provider'], [/\bGoDaddy\b/g, 'the US registrar'], [/\bVercel\b/g, 'the host'],
[/CLAUDE\.md/g, 'the project rules file'], [/\.claude\/agents\/?/g, 'the agent files '],
[/\/opt\/igneum[^\s`,;)]*/g, 'the prover host directory'], [/dl\.igneum\.network/g, 'the downloads host'],
[/log[-_]intake[-_]?key|LOG_INTAKE_KEY|intake[_-]?key/gi, 'the log key'], [/log-intake|LOG_INTAKE/g, 'the log intake'],
[/\bintake id\b/g, 'the upload id'], [/\+0100/g, 'a local-time offset'], [/\bBST\b/g, 'local time'],
[/\bTailscale\b|\bts\.net\b/g, 'the private network'], [/DESKTOP-[A-Z0-9]{7}/g, 'the PC'], [/MacBook/g, 'the laptop'],
[/\bhcloud\b/g, 'the cloud CLI'], [/igneum-seed[0-9]*/g, 'the seed node'], [/\/root\//g, '/<home>/'],
[/\/Users\/[^\s/`]+/g, '~'], [/C:\\Users\\[^\s\\`]+/g, '%USERPROFILE%'], [/~\/Desktop/g, '~/<folder>'],
[/192\.168\.\d+\.\d+/g, '<lan address>'], [/100\.\d+\.\d+\.\d+/g, '<private address>'],
];
const scrub = s => SCRUB.reduce((t, [re, r]) => t.replace(re, r), s);
// Inline markdown: code spans and links only; the ledger uses nothing else inside a status line.
function inline(s) {
let t = esc(s);
t = t.replace(/`([^`]+)`/g, (m, c) => `<code>${c}</code>`);
t = t.replace(/\[([^\]]+)\]\((https?:[^)]+)\)/g, (m, a, u) => `<a href="${u}" rel="noopener">${a}</a>`);
return t;
}
const lines = readFileSync(src, 'utf8').split('\n');
const entries = [];
let cur = null;
for (const l of lines) {
const m = /^### ([A-Z]\d+)\. (.*)$/.exec(l);
if (m) { cur = { id: m[1], title: m[2].trim(), quote: '', status: '', answer: '' }; entries.push(cur); continue; }
if (!cur) continue;
const s = l.trim();
if (!cur.quote && s.startsWith('"')) cur.quote = s.replace(/^"|"$/g, '');
else if (!cur.status && s.startsWith('Status:')) cur.status = s.slice(7).trim();
else if (!cur.answer && s.startsWith('Answer:')) cur.answer = s.slice(7).trim();
}
const SECTION = { M: 'Mining and chips', F: 'Finality and attacks', P: 'Proving and the zkEVM', E: 'Economics and the coin', G: 'Governance and the founders', C: 'Comparisons', L: 'Legal and regulatory', X: 'Launch and operations', D: 'Builders' };
function bucket(status) {
const s = status.toLowerCase();
if (/^(fixed|rolled out|rule fixed|spec fixed|rule implemented|rule written|written|designed)/.test(s)) return 'Fixed or built';
if (s.startsWith('conceded')) return 'Conceded';
if (s.startsWith('answered by design')) return 'Answered by design';
if (/^(answered with evidence|measured|simulation half)/.test(s)) return 'Answered with evidence';
if (/^(closed|decided)/.test(s)) return 'Closed by rule or decided';
if (s.startsWith('open')) return 'Open';
return 'Other';
}
function statusWord(status) {
const m = /^([^(:.]+?)(?=\s*[(:.]|$)/.exec(status);
return (m ? m[1] : status).trim();
}
function dateOf(status) {
const m = /(\d{1,2} October 2026)/.exec(status);
return m ? m[1] : '3 October 2026';
}
const ORDER = ['Open', 'Conceded', 'Fixed or built', 'Closed by rule or decided', 'Answered with evidence', 'Answered by design', 'Other'];
const MEANING = {
'Open': 'Nothing has settled it yet. The entry names what will',
'Conceded': 'The critic is right. "Stated" means the public text says so; "not yet stated" means it does not yet',
'Fixed or built': 'A code, spec or text change answers it, with the commit or the page named',
'Closed by rule or decided': 'A consensus rule or a decision by the owner answers it, dated',
'Answered with evidence': 'A measurement or a simulation exists and is named',
'Answered by design': 'A design rule answers it; no measurement is possible yet',
'Other': 'A status outside the six above, read the line',
};
const counts = {};
for (const e of entries) { const b = bucket(e.status); counts[b] = (counts[b] || 0) + 1; }
const partial = name => readFileSync(join(root, 'site', 'partials', name), 'utf8').trim();
const HEAD = partial('head.html'), NAV = partial('nav.html'), FOOT = partial('footer.html');
const intro = `This is every criticism the project expects, in the critic's words, with what was done about it and the date. ${entries.length} entries since 3 October 2026. Entries are never deleted; a status that changes keeps its history on the line. Where the critic was right the entry says Conceded. Where nothing has been done it says Open and names what settles it. The founder mined through the GPU years. Ethereum's move to proof of stake in September 2022 ended that income and the miners' place in that chain. This is one person building, with AI systems doing the engineering, the coin he wanted to exist for miners: GPU-mined, the miners are the provers, no founder allocation, every cost stated. Help is welcome and a team is wanted: cryptographers, node engineers, miners who will test. This ledger is the application form: pick an open row and write to <a href="mailto:hello@igneum.network">hello@igneum.network</a> with its id.`;
const countRows = ORDER.filter(b => counts[b]).map(b => `<tr><td class="num">${counts[b]}</td><td><button type="button" class="chip" data-filter="${esc(b)}">${esc(b)}</button></td><td>${esc(MEANING[b])}</td></tr>`).join('\n');
let body = '';
let lastSec = '';
for (const e of entries) {
const sec = SECTION[e.id[0]] || e.id[0];
if (sec !== lastSec) { body += `<h2 id="${e.id[0].toLowerCase()}">${esc(sec)}</h2>\n`; lastSec = sec; }
const b = bucket(e.status);
const word = statusWord(scrub(e.status));
const rest = scrub(e.status).slice(word.length).replace(/^[\s(:.]+/, '').trim();
body += `<article class="entry" id="${e.id}" data-bucket="${esc(b)}">
<div class="head"><span class="id">${e.id}</span><h3>${inline(scrub(e.title))}</h3><span class="date">${esc(dateOf(e.status))}</span></div>
<blockquote>${inline(scrub(e.quote))}</blockquote>
<div class="status"><span class="badge b-${b.toLowerCase().replace(/[^a-z]+/g, '-')}">${esc(word)}</span>${rest ? ` <span class="did">${inline(rest)}</span>` : ''}</div>
${e.answer ? `<details><summary>The answer as first written</summary><p>${inline(scrub(e.answer))}</p></details>` : ''}
</article>\n`;
}
const html = `<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
<title>Igneum ledger: every criticism, answered</title>
<meta name="description" content="Every criticism Igneum expects, in the critic's words, with what was done, the status and the date. ${entries.length} entries. Nothing deleted, nothing softened.">
<link rel="canonical" href="https://igneum.network/ledger">
<meta name="theme-color" content="#0C0C0E">
<meta property="og:type" content="website">
<meta property="og:site_name" content="Igneum">
<meta property="og:title" content="Igneum ledger: every criticism, answered">
<meta property="og:description" content="${entries.length} criticisms in the critic's words, with what was done, the status and the date.">
<meta property="og:url" content="https://igneum.network/ledger">
<meta property="og:image" content="https://igneum.network/og-small.png?v=3">
<meta property="og:image:width" content="256">
<meta property="og:image:height" content="256">
<meta property="og:image:alt" content="Igneum. Mined by GPUs. Proven by fire.">
<meta name="twitter:card" content="summary">
<meta name="twitter:title" content="Igneum ledger: every criticism, answered">
<meta name="twitter:description" content="${entries.length} criticisms in the critic's words, with what was done, the status and the date.">
<meta name="twitter:image" content="https://igneum.network/og-small.png?v=3">
<meta name="twitter:image:alt" content="Igneum. Mined by GPUs. Proven by fire.">
<link rel="icon" href="/favicon.ico" sizes="48x48">
<link rel="icon" href="/favicon-32.png" type="image/png" sizes="32x32">
<link rel="icon" href="/icon-192.png" type="image/png" sizes="192x192">
<link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180">
<link rel="manifest" href="/site.webmanifest">
<!-- head:start -->
${HEAD}
<!-- head:end -->
<style>
:root{--obsidian:#0C0C0E;--graphite:#16161A;--line:#2A2A30;--line-2:#3A3A42;--ember:#F2541B;--molten:#FFB35C;--bone:#F4F1EC;--ash:#9A9A9E;--ink-2:#C9C7C2;--max:1200px;--gutter:clamp(16px,4vw,32px);--sec:clamp(40px,6vw,72px)}
*{box-sizing:border-box}
body{margin:0;background:var(--obsidian);color:var(--bone);font-family:var(--f-sans);font-size:16px;line-height:1.55;-webkit-font-smoothing:antialiased;overflow-x:hidden}
a{color:var(--ember);text-decoration:none}a:hover{color:var(--molten)}
.wrap{max-width:var(--max);margin:0 auto;padding-inline:var(--gutter)}
.eyebrow{font-family:var(--f-mono);font-size:12px;letter-spacing:.18em;text-transform:uppercase;color:var(--ash)}
h1{font-family:var(--f-display);font-weight:900;font-size:clamp(30px,5vw,52px);line-height:1.08;margin:10px 0 18px}
h2{font-family:var(--f-display);font-weight:700;font-size:clamp(22px,3vw,30px);margin:var(--sec) 0 16px;padding-top:8px;border-top:1px solid var(--line);scroll-margin-top:84px}
h3{font-family:var(--f-sans);font-weight:600;font-size:17px;margin:0;flex:1 1 auto;min-width:0}
.intro{font-size:17px;color:var(--ink-2);max-width:76ch;margin:0 0 24px}
.tbl{overflow-x:auto;border:1px solid var(--line);border-radius:16px;background:var(--graphite);margin:0 0 20px}
table{border-collapse:collapse;width:100%;font-size:15px;min-width:520px}
th,td{padding:11px 14px;text-align:left;vertical-align:top;border-bottom:1px solid var(--line)}
th{font-family:var(--f-mono);font-size:12px;letter-spacing:.12em;text-transform:uppercase;color:var(--ash);font-weight:500}
tr:last-child td{border-bottom:0}
td.num{font-family:var(--f-display);font-weight:700;font-size:22px;color:var(--ember);white-space:nowrap}
.chip{background:none;border:1px solid var(--line-2);color:var(--bone);border-radius:999px;padding:6px 12px;font:inherit;font-size:14px;cursor:pointer}
.chip:hover,.chip.on{border-color:var(--ember);color:var(--molten)}
.toolbar{display:flex;flex-wrap:wrap;gap:8px 14px;align-items:center;margin:0 0 8px;font-size:14px;color:var(--ash)}
.toolbar input{background:var(--graphite);border:1px solid var(--line-2);color:var(--bone);border-radius:10px;padding:8px 12px;font:inherit;font-size:14px;min-width:220px}
.sections{display:flex;flex-wrap:wrap;gap:6px 14px;font-size:14px;margin:0 0 8px}
.entry{border:1px solid var(--line);border-radius:14px;background:var(--graphite);padding:16px 18px;margin:0 0 12px;scroll-margin-top:84px}
.entry.hide{display:none}
.head{display:flex;flex-wrap:wrap;align-items:baseline;gap:6px 12px}
.id{font-family:var(--f-mono);font-size:13px;color:var(--molten);flex:0 0 auto}
.date{font-family:var(--f-mono);font-size:12px;color:var(--ash);flex:0 0 auto}
blockquote{margin:10px 0;padding:10px 14px;border-left:3px solid var(--line-2);color:var(--ink-2);font-style:italic}
.status{font-size:15px;color:var(--ink-2)}
.badge{display:inline-block;font-family:var(--f-mono);font-size:12px;letter-spacing:.06em;text-transform:uppercase;padding:3px 8px;border-radius:6px;border:1px solid var(--line-2);color:var(--bone);margin-right:6px;vertical-align:middle}
.b-open{border-color:var(--ember);color:var(--ember)}.b-conceded{border-color:var(--molten);color:var(--molten)}.b-fixed-or-built{border-color:#5cb85c;color:#8fd48f}
code{font-family:var(--f-mono);font-size:13px;color:var(--bone);background:#0C0C0E;padding:1px 5px;border-radius:5px}
details{margin-top:8px;font-size:14px;color:var(--ash)}summary{cursor:pointer;color:var(--ash)}details p{margin:8px 0 0;color:var(--ink-2)}
.foot{margin-top:var(--sec)}
</style>
</head>
<body>
<!-- nav:start -->
${NAV}
<!-- nav:end -->
<main id="main" class="wrap">
<header style="padding-block:clamp(40px,6vw,72px) 8px">
<div class="eyebrow">Ledger · ${entries.length} entries · regenerated from the repository</div>
<h1>Every criticism, answered or conceded</h1>
<p class="intro">${intro}</p>
</header>
<div class="tbl"><table>
<thead><tr><th>Count</th><th>Status</th><th>Meaning</th></tr></thead>
<tbody>
${countRows}
<tr><td class="num">${entries.length}</td><td><button type="button" class="chip" data-filter="">All</button></td><td>Every entry. The sections: ${Object.entries(SECTION).map(([k, v]) => `<a href="#${k.toLowerCase()}">${esc(v)}</a>`).join(', ')}</td></tr>
</tbody></table></div>
<div class="toolbar"><input type="search" id="q" placeholder="Search the ledger" aria-label="Search the ledger"><span id="shown"></span></div>
${body}
<p class="intro" style="margin-top:var(--sec)">Source: <code>docs/fud-ledger.md</code> in the repository, rendered by <code>tools/ledger-page.mjs</code>. A criticism that is not here, or that shows an entry is wrong, is added with credit if wanted: <a href="mailto:hello@igneum.network">hello@igneum.network</a> or <a href="https://github.com/igneum-network/spec/issues" rel="noopener">an issue on the specification repository</a>.</p>
</main>
<!-- footer:start -->
${FOOT}
<!-- footer:end -->
<script>
(function(){
var chips=document.querySelectorAll('.chip'),entries=document.querySelectorAll('.entry'),q=document.getElementById('q'),shown=document.getElementById('shown'),f='';
function apply(){var t=(q.value||'').toLowerCase(),n=0;entries.forEach(function(e){var ok=(!f||e.getAttribute('data-bucket')===f)&&(!t||e.textContent.toLowerCase().indexOf(t)>=0);e.classList.toggle('hide',!ok);if(ok)n++;});shown.textContent=n+' of '+entries.length+' shown';chips.forEach(function(c){c.classList.toggle('on',c.getAttribute('data-filter')===f);});}
chips.forEach(function(c){c.addEventListener('click',function(){f=c.getAttribute('data-filter')||'';apply();});});
q.addEventListener('input',apply);apply();
if(location.hash){var el=document.getElementById(location.hash.slice(1));if(el)el.scrollIntoView();}
})();
</script>
</body>
</html>
`;
writeFileSync(out, html);
console.log(`${out}: ${entries.length} entries, counts ${JSON.stringify(counts)}`);