Funding plan: proof-system audit line item beside the hash cryptanalysis row

Scope (SP1 shard and aggregator guests, pinned ids and pin script, the node's
verifier path and record rules of spec 7.7 and 7.8, the version 2 RISC Zero
guest when it lands), deliverables, six candidate reviewers with published
zkVM audits and their sources, cost basis from public rate cards and
comparable engagement sizes, and when it bites. Totals refreshed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-06 11:36:10 +00:00
parent ee8b766470
commit b68ddd59b3

View file

@ -25,10 +25,11 @@ Columns: estimated cost with its basis; what is funded today; what depends on fu
|---|---|---|---|---|
| Development: founder and agents through mainnet (13 months) | No dollar figure: the founder's time and the agent tooling the founder already pays for. Basis: `CLAUDE.md` team section; `docs/fud-fixes.md` row 29 (method disclosed) | Founder's own means | No | Continues |
| Development: a contracted cryptographer for phases 1 and 2 (lottery hash soundness, VDF code against chiavdf, seed derivation; `docs/fud-fixes.md` row 71, O-1.4, O-4.1) | USD 80,000 to 150,000 for about six months part time. Basis: from memory of contract rates for applied cryptography, approximate | Founder's own means | No | Scope shrinks to the gate 1 review of the fair-lottery properties only; the VDF review moves to the audit row |
| Independent audit: the proof system (added 6 October 2026, section 2a). Scope: the SP1 shard guest and aggregator guest in `proving/igneum-prove` (`program`, `aggregator`, `core`: 2,494 lines of Rust on this branch), the pinned program ids (`elf/manifest.json`, `host/src/pinned.rs`) and the pin script (`pin-guests.sh`, `host/src/bin/pin.rs`), the node's verifier path and record rules in the execution layer (spec 7.7 and 7.8 in `docs/spec/07-execution.md`: the proof pool, `--mode verify` and `verify-segment`, the consensus checks on carried records, the chain rule, the unproven rule, the payouts), and the proof-system version 2 guest (RISC Zero) when it lands. Out of scope: the zkVMs themselves, which carry their own audits (section 2a). Deliverables: a published report; every fixed finding re-verified by the reviewer; the pinned ids re-derived by the reviewer from the sources with the pin script | Version 1 pass USD 120,000 to 250,000 at 6 to 10 reviewer-weeks; version 2 guest pass USD 40,000 to 100,000 at 2 to 4 reviewer-weeks; USD 160,000 to 350,000 in all. Basis: public per-engineer-week rates of USD 20,000 to 25,000 and the engineer-weeks of comparable zkVM and circuit audits, section 2a; approximate | Not funded | Yes | Not pausable. Version 2 does not activate on an unaudited guest, and mainnet does not ship on an unaudited verifier path: the dates move until it is paid. Section 2a says what breaks if it is skipped |
| Development: the second independent node client | Not in the 13-month plan (`docs/fud-fixes.md` rows 31, 47). Basis: decision pending | Not funded | Yes, entirely | Does not start |
| Independent review: finality rule v2 (gate 3, phase 4, the rule external review is paid to break) | USD 50,000 to 100,000. Basis: a focused review of one consensus rule plus its simulation by two reviewers over a few weeks, from memory, approximate | Founder's own means | No | Not pausable: the roadmap says the phase 4 gate is "finality design passes external review". If it cannot be paid, phase 4 does not close and the dates move |
| Independent audit: the node fork (consensus delta, p2p, difficulty, header validation, the pow engine) before public testnet | USD 60,000 to 120,000. Basis: the delta is listed row by row in `docs/fork-divergence.md`; the base is rusty-kaspa, already audited upstream, approximate | Founder's own means, second in order after the finality review | Partly: a second pass after the attack harness closes its stubs | The single pass is kept; the second pass waits. Public testnet does not open without the first pass |
| Independent audit: execution layer and proving integration (revm driver, two-dimensional gas, proof records, the veto, the `ProofSystem` version 1 integration) before mainnet | USD 80,000 to 150,000. Basis: an EVM-integration audit of a new client's execution path, from memory, approximate | Not funded | Yes | Mainnet moves until it is paid. Mainnet does not ship with an unaudited execution layer |
| Independent audit: execution layer (revm driver, two-dimensional gas, the segment cut, the native statement) before mainnet. The proof records, the veto, the verifier path and the `ProofSystem` integration moved to the proof-system audit row on 6 October 2026 | USD 80,000 to 150,000. Basis: an EVM-integration audit of a new client's execution path, from memory, approximate; the cost was not reduced when the proving scope moved out, because the revm driver and the gas rules are the bulk of it | Not funded | Yes | Mainnet moves until it is paid. Mainnet does not ship with an unaudited execution layer |
| Independent audit: the official client and release process (spec 08: reproducible builds, release key, update path) | USD 20,000 to 40,000. Basis: a short application security review, from memory, approximate | Not funded | Yes | The one-click app ships at testnet unaudited and says so on the download page; the audit lands before mainnet or the app does not carry the mainnet release key |
| Infrastructure: the 20-node cloud devnet | USD 476 per month for 20 nodes (Hetzner API prices of 3 October 2026, net, `docs/plans/cloud-devnet.md`); about USD 6,000 for the 13 months, plus rented GPU hours for the hourly-compile and shard measurements at USD 0.22 to 0.74 per card hour (RunPod, 3 October 2026): under USD 1,000 over phase 2 | Founder's own means | No | Node count drops to 8 (two per location); the rented GPU hours are replaced by the project's own cards |
| Infrastructure: seed nodes, site, observer database, domains | Seed nodes USD 50 to 80 per month for three to five (`docs/plans/seed-nodes.md`); the site and the observer's database are on free or near-free tiers today, approximate; 15 domains at the registrar's renewal price, approximate USD 500 per year | Founder's own means | No | Three seeds not five; nothing else changes |
@ -38,19 +39,69 @@ Columns: estimated cost with its basis; what is funded today; what depends on fu
| Challenge reward: the reproduction reward of `docs/benchmarks/proving-e2e.md` 8.1 (a fixed, equal, disclosed amount per unrelated operator) | USD 1,000 per operator per workload set, three operators, about USD 3,000 per campaign. Basis: covers electricity and a day of attention, approximate | Not funded | Yes | Reproduction is asked for without a reward; the standard allows that |
| Legal: counsel on the entity, the promotions question, the testnet payment terms, the no-custody structure of the job market (`docs/fud-fixes.md` rows 46, 58, 59) | USD 20,000 to 50,000. Basis: from memory, approximate | Founder's own means | No | Continues; it gates public text, not code |
## 2a. The proof-system audit, in parts
Added 6 October 2026. The row in section 2 is the summary; this is its basis. Nothing here is outreach: no firm has been contacted and none is engaged.
### What is in scope and what is not
| Part | Where it lives | Why it is in scope |
|---|---|---|
| SP1 shard guest | `proving/igneum-prove/program`, `core` | The statement every node's veto compares against (7.6); a guest bug is a wrong statement with a valid proof |
| SP1 aggregator guest | `proving/igneum-prove/aggregator` | Verifies every shard proof and the previous segment proof by recursion (7.8 item 1); a missing check here is a forged chain of segments |
| Pinned program ids and the pin script | `elf/manifest.json`, `host/src/pinned.rs`, `pin-guests.sh`, `host/src/bin/pin.rs` | The ids are what consensus compares `shard_vk` and `agg_vk` against (7.8 item 5); the reviewer re-derives them from the sources |
| The node's verifier path and record rules | Execution layer, spec 7.7 and 7.8: the proof pool, `--mode verify` and `verify-segment`, the consensus checks on carried records, the chain rule, the unproven rule, the payouts | A record that passes the checks pays; a verifier that accepts the wrong proof pays a forger |
| Proof-system version 2 guest (RISC Zero) | Behind the `ProofSystem` seam, not written yet (`docs/plans/proving-v1.md`, AMD and Apple row) | A second guest and a second pinned id; audited when it lands, before its activation |
| Out of scope: SP1 and RISC Zero themselves | Their own repositories | Each carries its own published audits (table below); this audit reads them and does not repeat them |
### Candidate reviewers with published zkVM audits
Firms that have published audits of SP1, RISC Zero, Jolt or zkEVM circuits. Listed for scoping only; no one has been contacted.
| Reviewer | What they audited | When | Source |
|---|---|---|---|
| Veridise | RISC Zero zkVM: the recursive STARK-to-STARK and STARK-to-SNARK circuits, receipt verification, the V2 RISC-V zkVM in Zirgen, host and prover; 96 person-weeks, 6 analysts over 16 weeks. Also SP1 recursion (June 2024) and the SP1 v1 report in the SP1 repository | 29 July to 13 December 2024 (RISC Zero); June 2024 (SP1) | veridise.com, RISC Zero zkVM 2025-02-24 archive page; veridise.com Succinct archive page; `succinctlabs/sp1/audits/veridise.pdf` |
| Zellic | SP1 Hypercube: 13.5 person-weeks, two consultants over 16 calendar weeks, kick-off 18 August 2025, final report 23 December 2025, 3 critical and 7 high findings. Also an SP1 RV32IM design review (December 2024) and Scroll zkEVM circuits (May 2024, with 4 critical findings) | August to December 2025 (SP1 Hypercube) | `succinctlabs/sp1/audits/hypercube-zellic.pdf` and `zellic.pdf`; reports.zellic.io Scroll zkEVM |
| Hexens | RISC Zero zkVM (22 August to 26 October 2023), the circuit (November 2023 to January 2024), the STARK-to-SNARK circuit (February to March 2024), the SNARK verifier contract (2024), PoVW (July to August 2025) | 2023 to 2025 | `risc0/rz-security/audits/README.md` |
| Trail of Bits | Scroll zkEVM circuits, three waves plus EIP-4844: wave 3 was the proof compression and aggregation circuit, the MPT hash scheme, precompile circuits, the prover and the transaction circuit, two consultants, 14 August to 19 September 2023, nine engineer-weeks; wave 2 was six weeks with 3 high findings | April 2023 to April 2024 | Trail of Bits Scroll wave 3 report (bugs.zksecurity.xyz dataset); trailofbits.com library, Scroll zkEVM wave 2; docs.scroll.io audits page |
| zkSecurity | Jolt (a16z): a joint review published 19 November 2024 that found three forgeable-proof bugs (truncated traces accepted, zero mask in output check, prover-controlled memory layout), plus the uni-skip verifier bug of 9 May 2026. Also RISC Zero's Solana Groth16 verifier and r0vm-helios (2025) | 2024 to 2026 | blog.zksecurity.xyz, Jolt findings and Jolt uni-skip posts; `risc0/rz-security/audits/README.md` |
| rkm0959 (solo, reports published through KALOS) | SP1 v1.0.0, v3.0.0 and v4.0.0: the v4 audit ran 25 November to 13 December (2024) for 3 engineer-weeks and found the `chip_ordering` and `is_complete` verifier bugs of SP1 v3 | 2024 | `succinctlabs/sp1/audits/kalos.md`, `rkm0959.md`, `sp1-v4.md` |
SP1 has also been through a Cantina competition (3 to 23 June 2024, 25 issues, 0 critical) and a Code4rena contest (15 September to 15 October 2025, USD 112,500 prize pool, 42,043 lines in scope). Those are the zkVM's own coverage, not a model for this audit, whose scope is 2,494 lines of guest code plus the host's pinning and verify paths (1,687 lines) and the node's record rules.
### Cost basis
| Input | Value | Source |
|---|---|---|
| Top-tier per-engineer-week rate | USD 25,000 (Trail of Bits, OpenZeppelin); USD 20,000 per week (Runtime Verification); USD 32,500 to 48,000 per team-week (Spearbit) | 7blocklabs 2026 audit-cost article, quoting Arbitrum DAO ARDC procurement proposals |
| Mid-tier per-auditor-week rate | USD 6,000 | Zealynx published standard rate |
| Comparable engagement, circuits of the aggregation and precompile class | 9 engineer-weeks (Trail of Bits, Scroll wave 3); 6 weeks (Scroll wave 2) | As above |
| Comparable engagement, one zkVM version | 13.5 person-weeks (Zellic, SP1 Hypercube); 3 engineer-weeks (rkm0959, SP1 v4) | As above |
| Comparable engagement, a whole zkVM | 96 person-weeks (Veridise, RISC Zero) | As above; this is the out-of-scope class |
Reviewer-weeks assumed: 6 to 10 for the version 1 pass (two reviewers, three to five weeks: guests, pinning, verifier path, record rules), 2 to 4 for the version 2 guest pass (one reviewer, the new guest and its pinned id against the same statement). At USD 20,000 to 25,000 a week that is USD 120,000 to 250,000 and USD 40,000 to 100,000. At the mid-tier rate the same weeks cost USD 36,000 to 60,000 and USD 12,000 to 24,000; the plan budgets the top-tier figure because every firm in the table above sits in that bracket. Approximate throughout.
### When it bites
| Moment | What must be true | What breaks if it is skipped |
|---|---|---|
| Before the version 2 (RISC Zero) guest activates | The version 2 pass is done and the second pinned id re-derived by the reviewer | A guest that proves a wrong statement under a valid proof is paid from the pool on every segment it attests; with the mandatory-proof rule of 7.8 item 10 on, a wrong aggregated proof could make honest blocks invalid or forged ones valid |
| Before mainnet | The version 1 pass is done, findings fixed and re-verified, both pinned ids re-derived | The same, on the chain that carries value: a forged shard or segment proof pays the forger from the escrow, and the native statement bounds the damage to payouts only while verification stays off the consensus path (7.7 item 4, 7.8 item 8); the day proofs become a condition of validity, an unaudited verifier path is a consensus bug |
| Every re-pin | Not an audit, but the reviewer's re-derivation recipe is rerun by the team and the ids match | A pinned id nobody can reproduce is a program nobody has read |
## 3. Totals
| Bucket | Approximate total | Funded today |
|---|---|---|
| Development (cryptographer; founder time unpriced) | USD 80,000 to 150,000 | Yes |
| Independent review and audits | USD 210,000 to 410,000 | The finality review and the first node pass: USD 110,000 to 220,000. The execution and client audits, USD 100,000 to 190,000: no |
| Independent review and audits | USD 370,000 to 760,000 | The finality review and the first node pass: USD 110,000 to 220,000. The proof-system, execution and client audits, USD 260,000 to 540,000: no |
| Infrastructure | USD 8,000 to 10,000 through mainnet | Yes |
| Incident response | USD 40,000 through the first mainnet quarter | No |
| Challenge rewards | USD 78,000 standing plus USD 3,000 per campaign | No |
| Legal | USD 20,000 to 50,000 | Yes |
| Total | USD 440,000 to 740,000 through the first mainnet quarter, plus standing bounties | About USD 220,000 to 430,000 funded; about USD 220,000 to 310,000 unfunded, all of it after public testnet |
| Total | USD 600,000 to 1,090,000 through the first mainnet quarter, plus standing bounties | About USD 220,000 to 430,000 funded; about USD 380,000 to 660,000 unfunded, all of it after public testnet |
The unfunded half is the half that comes after the chain exists and before and just after it launches: the execution audit, the client audit, incident response and the bounties. Each row says what pauses. Two things never pause and instead move the date: the finality review (phase 4 gate) and the execution audit (mainnet). The plan is to delay rather than to launch unreviewed.
The unfunded half is the half that comes after the chain exists and before and just after it launches: the proof-system audit, the execution audit, the client audit, incident response and the bounties. Each row says what pauses. Three things never pause and instead move the date: the finality review (phase 4 gate), the proof-system audit (version 2 activation and mainnet) and the execution audit (mainnet). The plan is to delay rather than to launch unreviewed.
## 4. What the 1% fee could be, and why it is not counted