diff --git a/site/bench.html b/site/bench.html index cf2e03751..ccd85f4c6 100644 --- a/site/bench.html +++ b/site/bench.html @@ -13,10 +13,10 @@ - - + + - + diff --git a/site/build.mjs b/site/build.mjs index 65716de7c..9ed7ddf62 100644 --- a/site/build.mjs +++ b/site/build.mjs @@ -58,10 +58,10 @@ function meta(title, desc, path) { - - + + - + diff --git a/site/index.html b/site/index.html index a551af837..0ff2f09d0 100644 --- a/site/index.html +++ b/site/index.html @@ -12,14 +12,14 @@ - - - + + + - + - + @@ -305,9 +305,9 @@ footer .wrap{padding-block:48px 32px}
rollup · batch proofat testnet
bridge · state proofat testnet
rollup · fault proofat testnet
-
IGN burned from jobsat launch
+
IGN burned from jobsphase two
-

The same cards sell proofs to rollups and bridges.

+

The same cards sell proofs to rollups and bridges. Jobs are paid on the customer's chain at launch; settlement in IGN with a 10% burn follows the proof bridge in phase two.

Read more in the litepaper diff --git a/site/litepaper.html b/site/litepaper.html index 588ae777f..e01cd0bd7 100644 --- a/site/litepaper.html +++ b/site/litepaper.html @@ -12,14 +12,14 @@ - - - + + + - + - + @@ -310,7 +310,7 @@ body.all .pager{display:none}

Proving: the miners are the provers

Every Igneum block is proven with a zero-knowledge proof, and the miners produce it. Proving is the one useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not, and a phone can check it in milliseconds.

How a block gets proven

-

Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Miners claim shards with a small bond, prove them on consumer cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch. Because the proof computes the state from the ordered sequence, a block with a wrong state cannot exist. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.

+

Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond. Provers run them on consumer cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch. Because the proof computes the state from the ordered sequence, a block with a wrong state cannot exist. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.

The proving budget

Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Shard size will be set so a 12 GB card proves one shard in about 20 seconds. That number is the first gate on the roadmap and has not been measured yet; once it has, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface, so Igneum can adopt a better proof system when one exists by a miner-signalled release, and runs for ever on the current one if none is adopted.

Proving for everyone else

@@ -325,7 +325,7 @@ body.all .pager{display:none}

Every 30 seconds of chain a checkpoint forms, deep enough past the tip that the DAG will not reorder it. Every miner with at least 100 blocks in the last 30 days signs it, and the checkpoint locks when signatures representing two thirds of the active mining weight arrive. Once a checkpoint is locked it overrides the heaviest chain, so no amount of fresh hashrate can reorganise past it. In the chain's first month the weights behind those locks are thin, because nobody has a long history yet, and the chain leans on proof of work and the one-hour depth limit the way every new proof-of-work chain does.

The word sustained is the whole defence. Block rewards go to whoever mines, new or old. The right to lock history is earned.

A miner's vote weight is simply the blocks it has mined over the trailing 30 days, measured by work, so splitting into many keys buys nothing and joining a pool costs nothing. Hashrate that arrived today holds almost none of it. Even an attacker who brought the whole network's hashrate would need ten days of mining in public to hold a third of the weight, and twenty days to hold two thirds. At 51% of the network they never reach two thirds at all while the honest miners keep mining. Rental is priced by the hour. The only route left is to drive honest miners off the chain and hold two thirds for a month on the public hashrate charts, which is the same limit Bitcoin lives with, with a month's warning attached.

-

Two further rules close the gaps. Only miners who are present count: a key that stops signing drops out of the denominator within two hours, so a silent minority cannot freeze finality and a lock never waits for miners who have left. And Kaspa's one-hour merge-depth bound limits any reorganisation beneath the latest lock. Signing two different checkpoints at the same height is equivocation, provable by anyone, and it strips the key of its vote for 30 days.

+

Two further rules close the gaps. A key that stops signing drops out of the active count within two hours. A lock still needs 56.7% of all 30-day weight, so if more than about 42% of weight goes quiet finality pauses until it returns or ages out, up to 30 days, and the chain runs on proof of work meanwhile. The node reports the pause. And Kaspa's one-hour merge-depth bound limits any reorganisation beneath the latest lock. Signing two different checkpoints at the same height is equivocation, provable by anyone, and it strips the key of its vote for 30 days.

What is not here

No stake. No coin-holder class votes on anything. No anchoring into Bitcoin or any other chain. Nothing in Igneum's consensus depends on anything outside Igneum.

@@ -389,8 +389,8 @@ body.all .pager{display:none} 0%Treasury, foundation, team or stakeThere is no coin-holder class in consensus and no tax on emission -

Where the price comes from

-

The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits two ways: 80% to the miner and provers of that block, 20% to the apps whose code ran, by gas consumed inside each. External proving fees pay 90% to the provers who delivered and burn 10%. The hard cap fixes supply. Demand comes from use of the chain and from outsiders buying proofs, and both reduce supply as they happen. Emission is untouched by any of this: every coin minted still goes to miners and provers.

+

Where fees go

+

The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits two ways: 80% to the miner and provers of that block, 20% to the apps whose code ran, by gas consumed inside each. External proving fees pay 90% to the provers who delivered and burn 10%. The hard cap fixes supply. Emission is untouched by any of this: every coin minted still goes to miners and provers.

No fund, no foundation, no fee to the team

There is no development fund. A switch that routes money to an address somebody controls is the first thing a critic points at, so Igneum has none. The protocol carries no fee to any team, foundation or fund. The team earns in the open: it runs provers in the job market and collects the app share on the contracts it deploys, like anyone else. If the community ever wants a grant mechanism, miners can add one by signalling.

@@ -501,6 +501,7 @@ body.all .pager{display:none}
  • A chip is impossible. No. A chip is pointless, because the target moves before it ships. The honest efficiency ceiling for a fixed chip on a memory-bound program is under 2x, approximate, and Igneum's generator changes under it every hour.
  • A guaranteed income floor. No. External proving is a small market today. Igneum's miners have the lowest cost in it, which is an edge and nothing more.
  • Finality that no amount of hardware can break. No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded to one hour. Reaching a third takes at least ten days of the whole network's hashrate, in public. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose.
  • +
  • Finality that never pauses. No. A lock needs 56.7% of all 30-day mining weight. If more than about 42% of that weight stops signing, finality pauses until it returns or ages out of the window, up to 30 days. The chain keeps running on proof of work and the node reports the pause.
  • A finished protocol. The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.
  • Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything.

    diff --git a/site/live.html b/site/live.html index f6559bf4f..8dbc67f89 100644 --- a/site/live.html +++ b/site/live.html @@ -12,14 +12,14 @@ - - - + + + - + - + diff --git a/site/og-square.png b/site/og-square.png new file mode 100644 index 000000000..900b01f23 Binary files /dev/null and b/site/og-square.png differ