Merge mission: the last research round (five lanes: past, unfinished, future, invent, reinvent) and The Igneum Mission, the closed list of twelve

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-07 08:22:14 +00:00
commit d91fe9bbb3
7 changed files with 2404 additions and 0 deletions

View file

@ -0,0 +1,566 @@
# The last mission, lane 3: the far future, 2030 to 2036
Written 7 October 2026 by the future lane. Scope: the ten-year axes Horizon lane 7 did not cover, and the years 2030 to 2036 on the axes it did. Lane 7's rows to 2030 (`docs/analysis/horizon/frontier.md` 2.1 to 2.6) are taken as given and not repeated; where this lane disagrees, the row is named and the reason sourced. Every figure from memory is labelled approximate. Every figure from a source names it, with a URL in the sources list and the access date (all accessed 7 October 2026 unless stated). Times are UK. The arithmetic behind sections 2, 3, 4, 6 and 7 is `model.py` in this lane's scratch directory (`scratchpad/mission-future/`), reproduced in the tables.
The design this lane tests (horizon-2026-10.md section 1): an hourly random GPU program, a 256 MiB cache over a daily multi-GB dataset (2 GiB at genesis, doubling at years 4, 12, 28), latency-shadow work in a six-rung N ladder stepped by 90 percent miner signal, class v5 (dataset from chain state) as a candidate, miner-only finality with BLS vote keys weighted by 30 days of blocks, SP1 zkEVM proving by miners (the 20 percent pool), 100 IGN a block gliding to a 1 percent tail, no stake, no dev fund, no other chain in consensus.
## 0. Progress
| Time (UK) | State |
|---|---|
| 08:2x | Brief read: CLAUDE.md, frontier.md 2 and 6, algorithm.md 5, chip-model-v3.md 5, horizon-2026-10.md 1, finality-in-proof.md 4, 51-percent.md, bench-log rental entry |
| 08:3x to 08:5x | 50 web searches (the session's search budget ran out at 50; the rest went by direct fetch), 27 primary fetches |
| 08:5x | Model run (`model.py`): emission by year, chip thresholds, rental curve, heat credit, PQ bytes, wallet battery |
| 08:5x to 09:00 | Sections 1 to 11 written, 566 lines, copy-law check clean (no em or en dashes, ASCII only) |
| 09:00 | DONE. File handed to the coordinator. Nothing committed; nothing on the devnet touched; no build or measurement run |
The tiers, used in every row: home miner with one 8, 12, 16, 24 or 32 GB card; a rig; a pool user; on Windows, Linux, macOS; NVIDIA, AMD, Apple.
## 1. GPU and memory roadmaps, 2027 to 2036
### 1.1 The roadmap, sourced
| Item | What is announced or reported | Source | Label |
|---|---|---|---|
| HBM4 | Mass production at Samsung and SK hynix from February 2026; 2,048-bit interface, 8 Gbps a pin, about 2 TB/s a stack; 12-high 36 GB; SK hynix 16-high 48 GB from Q3 2026; Micron samples over 11 Gbps, 2.8 TB/s | TrendForce 9 Jan 2026; EE Times CES 2026; Astute Group | cited |
| HBM4 price | About USD 550 a 36 GB stack, USD 15.3 per GB (factory gate) | siliconanalysts.com/tools/hbm-analysis | approximate (the site cites no primary) |
| HBM4E | Late 2027 to 2028; 14 to 16 Gbps a pin, 3.6 to 4.0 TB/s a stack; 16-high; custom base dies on TSMC N3 (the GUC and TSMC "C-HBM4E" line, 12.8 GT/s by 2027); Samsung HBM4E samples May 2026 at 3.6 TB/s | TrendForce 23 Dec 2024; Tom's Hardware (TSMC/GUC); TechTimes 30 May 2026 | cited |
| HBM on a consumer card | None announced. The Feynman datacentre architecture (2028) "supports HBM"; no consumer HBM part from NVIDIA, AMD or Intel on any roadmap found | Wikipedia Feynman page; the 2027 to 2028 rumour set | cited (absence) |
| GDDR8 | No JEDEC standard. SK hynix's roadmap to 2031 lists "GDDR7-Next" for 2029 to 2031 | Tom's Hardware (SK hynix roadmap); TechSpot | cited |
| GDDR7 devices | 2 GB ended at Micron (Sep 2026); 3 GB shipping at USD 60 to 70; 4 GB and 6 GB devices reported for 2027 to 2028 | chip-model-v3 5.1; wccftech; club386 | 3 GB cited, 4 and 6 GB rumour |
| RTX 60 (Rubin GR20x) | Late 2027 slipped to 2028; GDDR7; the 6090 reported at 512-bit with 32 GB or 48 GB | TweakTown; wccftech; BigGo | rumour |
| AMD RDNA 5 / UDNA | Mid-2027 to 2028; GDDR7 at 36 Gbps; flagship "AT0" 154 CUs, 36 GB on 384-bit, 1.7 TB/s, 380 W; shares a chiplet design with the next Xbox; GDDR7 support landed in the Linux driver | TweakTown; TechPowerUp; Tom's Hardware driver note | rumour, driver patch cited |
| NVIDIA consumer chiplets | Nothing reported; Rubin consumer parts described as monolithic | the same rumour set | approximate |
| Strix Halo class | Strix Halo: 256-bit LPDDR5X-8000, 256 GB/s. Medusa Halo (2027 to 2028): LPDDR6 on 256-bit (461 GB/s) or 384-bit (691 GB/s) | VideoCardz; hardware-corner.net | rumour |
| Apple | M5 Max: up to 128 GB unified, 614 GB/s (40-core GPU), 460 GB/s (32-core); M5 Ultra Mac Studio August 2026 | Apple newsroom 3 Mar 2026 and Aug 2026 | cited |
| LPDDR6 | JESD209-6 published July 2025; 2 sub-channels a die, 12 DQ each, 4 CA each; activate timings not public | JEDEC press release | cited; timings unknown |
| DDR5 | 32 banks in 8 groups of 4 (x4/x8); JESD79-5D Nov 2025; tFAW a four-activate window | JEDEC; DDR5 core datasheet | cited |
| The latency floor | "The latencies of three fundamental DRAM operations have not improved significantly in the past 18 years"; improvements "relatively stagnant for the last two decades" | Lee et al. (arXiv 1604.08041); Chang et al. (arXiv 1805.03154) | cited |
### 1.2 What it means for the memory-latency-bound hash
The hash advances one dependent 4-byte read per memory latency; the rate is activates per tFAW window times channels, and energy is per activate (chip-model-v3 5.3). Pin speed does not move it. So the ten-year question is only: do channels per watt per dollar move, and does tRC or tFAW move. The sources say tRC has been flat for about twenty years, and no DRAM roadmap to 2031 (SK hynix) names a row-cycle improvement. HBM4 doubles channels per stack (lane 7, 2.3). HBM4E adds pin speed and a custom base die, not channels. GDDR7-Next is 2029 to 2031 and unspecified. Consumer HBM does not exist on any roadmap to 2028.
| Year | Flagship consumer memory (projected) | Random reads per second, flagship (approximate) | Mid-tier card (12 to 16 GB) | Tier that wins or loses against 2026 |
|---|---|---|---|---|
| 2026 | 32 GB GDDR7, 512-bit, 16 devices | 17.5 G measured (5090) | 12 GB, 192-bit, 6 devices: about 6.5 G | baseline |
| 2028 | 36 to 48 GB GDDR7, 384 to 512-bit (RDNA 5 rumour, RTX 60 rumour) | 16 to 21 G: the same, capacity adds no channels | 16 to 18 GB on the same channel count (3 GB devices): the same rate | nobody: a 2026 card keeps its rate against a 2028 card |
| 2031 | 48 to 64 GB GDDR7-Next (SK hynix window) | unknown; if channels per device rise to 8 (approximate guess), 1.5 to 2x | 24 GB mid-tier on the same count | the 2026 owner falls to 0.5 to 0.7x of the new card, the normal GPU cadence |
| 2036 | 64 to 96 GB (extrapolation of lane 7's 1.167 a year); HBM on a halo consumer part possible but unannounced | 2 to 4x of 2026 if a consumer HBM4-class part ships; otherwise 1.5 to 2x | 32 GB mid-tier | the 8 and 12 GB tiers are gone from the installed base (Steam trend, algorithm.md 5.6), not from the hash |
Apple and APUs: the M5 Max's 614 GB/s is a 512-bit LPDDR5X bus (approximate); LPDDR activates are the same DRAM physics, so the Apple tier stays "0.78 uJ per hash, 21 W" class (algorithm.md 5.3a), the best per joule and the worst per dollar (USD 129 per MH/s). Medusa Halo on 384-bit LPDDR6 would be a 24 to 36 channel part (approximate: 2 sub-channels a die): a mid-tier card's read rate at laptop watts. Consequence per tier: Apple and APU miners stay the per-joule leaders and never the per-dollar ones; nothing in the hash changes that in ten years.
### 1.3 The cache, the dataset schedule and the ladder, re-read against the roadmap
| Design item | Roadmap fact | Verdict | Recommendation |
|---|---|---|---|
| 256 MiB cache "above every GPU's on-die cache" (the spec's rule) | 5090 L2 96 MB, GB202 128 MB; MI300X carries 256 MB Infinity Cache (datacentre, approximate from memory); RDNA 3's 7900 XTX 96 MB; no consumer part at 256 MB announced | Safe to 2028. At risk from 2029 to 2031 if a consumer part ships a 256 MB last-level cache, which the datacentre already does | Add a cache-size rung to the era-draw ladder beside N (256 to 512 MiB), stepped by the same 90 percent signal, in place of the fixed year-4 doubling alone; the trigger is a shipped consumer part with LLC at or over the cache size |
| Dataset 2 GiB, doubling at years 4, 12, 28 | Card memory 32 GB now, 48 to 64 GB by 2030 (lane 7); one HBM3 stack holds 24 GB | Right. The dataset is not a lever against the stored-dataset chip (chip-model-v3 5.7) and never binds a tier before year 12 (algorithm.md 5.6) | Hold the schedule; the public card-lifetime sentence should carry the prover footprint, not the dataset (algorithm.md 5.6's one change) |
| N ladder rungs measured on 2026 cards | The honest card's bind point moves with each generation: a 2028 card with the same read rate and 1.5x the ALUs binds at a higher N; HBM4 doubles the chip's rate per stack | Rungs are a 2026 measurement. They are the right shape and the wrong numbers for 2029 | Re-measure the rungs per card generation (the Steam top-10 cards each era) and publish the bind points; the signal mechanism already lets miners refuse a rung their cards cannot hold, so no genesis change, only a measurement duty written into the era-draw docs |
| C-HBM4E custom base die (2027 to 2028) | The base die under the stack becomes a logic die on N3 that a customer designs (TSMC and GUC) | This is the f = 1 chip's controller moved under the memory: the chip-model's "controller and PHY die beside it, 10 W, USD 50, plus a USD 200 one-stack interposer" row (5.3) collapses into the base die. Lane 7's 2.3 did not price it | Disagreement with lane 7 row 2.3 "HBM4 one stack (2028)": the controller and interposer lines fall toward zero, so the HBM4 chip's dollars per MH/s fall below the USD 2.8 GDDR7 figure by 2028, approximate. The answer is unchanged in kind (N, the price per joule) and larger in degree; section 2 carries it |
Per tier, section 1 in one line each: 8 GB (mines to year 12, never proves beside its miner); 12 GB (mines to year 28, loses mine-and-prove at year 4); 16 GB (mines and proves to year 12); 24 and 32 GB (unconstrained to 2036 on every roadmap found); rig (the rate per card is flat through 2028, so a 2026 rig is a 2028 rig); pool user (the pool's share tracks the installed base, which loses the 8 GB tier by 2030); Windows and Linux (no change); macOS (per-joule best, per-dollar worst, both for ten years); NVIDIA (channel count flat to 2028); AMD (RDNA 5 brings GDDR7, a 36 GB flagship: AMD's first competitive random-read part since the 9070 XT's 2.4 to 2.7 G); Apple (as macOS).
## 2. The ASIC maker's economics, 2026 to 2036
### 2.1 Inputs
| Input | Value | Source |
|---|---|---|
| Mask set, total NRE: TSMC 28 nm | USD 1 M, 1.8 M | siliconanalysts.com/data/wafer-pricing (Sep 2026) |
| 16 nm | 1.8 M, 3.2 M | same |
| 7 nm | 3.5 M, 5.5 M | same |
| 5 nm | 6.5 M, 10 M | same |
| 3 nm | 15 M, 22 M; design cost of a 3 nm chip USD 400 to 600 M all-in | same; siliconanalysts tsmc-3nm-cost |
| 2 nm | masks USD 15 to 30 M; design cost quoted at USD 724 M | semiwiki thread; siliconanalysts | approximate |
| A16, A14 | no mask quote found; "capex per 1,000 wafers at A14 higher than N2" | semiwiki A14 thread | approximate |
| Wafer, 300 mm | 28 nm 3,000; 16 nm 5,500; 7 nm 9,500; 5 nm 20,000; 3 nm 20,000 (range to 27,000) | siliconanalysts wafer-pricing | cited |
| Leading-edge tapeout, all-in | USD 30 M to 100 M+ at 3 to 5 nm; 5 to 30 M at 7 to 28 nm | siliconanalysts tapeout guide, 1 Mar 2026 | cited |
| The f = 1 chip | 166 MH/s, 78 W bare, 228 W with a 150 W shadow core at k = 1; USD 470 of memory, controller and board; USD 2.8 per MH/s | chip-model-v3 5.4, lane 7 2.3 | model |
| The honest card | 5090 at class v4: 3.27 uJ, 431 W cap, 132 MH/s; USD 1,999 MSRP | algorithm.md 5.3a | measured |
| Emission (model) | 100 IGN a block, 90-day ramp from 10 percent, monthly glide at 2.9 percent, tail 1 percent a year from year 11.4 | tail-emission.md | model |
| Rental equilibrium | hash joins until rent equals subsidy: 39, 156, 780 GH/s at USD 0.005, 0.02, 0.10 per IGN | security-budget.md via 51-percent.md | model |
Emission by year from the model (IGN, approximate): year 1 2.32 B, year 2 1.87 B, year 3 1.31 B, year 4 0.92 B, year 5 0.65 B, year 6 0.46 B, year 7 0.32 B, year 8 0.23 B, year 9 0.16 B, year 10 0.11 B; supply 4.18 B at the end of year 2, 7.07 B at year 5, 8.33 B at year 10.
### 2.2 The decision tree, written out
The maker chooses a target share s of the hash and a node. Revenue over the chip's two-year life is s x E2 x p, where E2 is the two-year emission and p the IGN price. The fleet needed is s/(1 - s) x H(p), and at the rental equilibrium H(p) = 7.8 M MH/s per USD of price, so the fleet's cost is also linear in p: 0.43 x 7.8 M x USD 4.64 per MH/s (the chip's two-year cost per MH/s with power at USD 0.05 per kWh, model) against two-year revenue per MH/s of 0.0117 x 17,520 = USD 205. The fleet term is 2 percent of revenue and drops out. The project pays when p is over p* = C_proj / (s x E2), and the market cap at which it pays is p* x supply. At s = 0.30 (an economic miner just under the veto third):
| Node (project all-in) | Years 1 to 2 (E2 = 4.18 B) | Years 3 to 4 (2.24 B) | Years 5 to 6 (1.10 B) | Years 7 to 8 (0.55 B) | Years 9 to 10 (0.27 B) |
|---|---|---|---|---|---|
| 28 nm controller only, no shadow core (USD 5 M) | p* 0.0040, cap USD 17 M | 0.0075, 48 M | 0.0151, 114 M | 0.0306, 247 M | 0.0620, 517 M |
| 28 nm controller + N5 shadow core (USD 30 M) | 0.0239, 100 M | 0.0447, 287 M | 0.0906, 682 M | 0.1836, 1,481 M | 0.3718, 3,099 M |
| N3 single die, controller + shadow + lanes (USD 60 M) | 0.0478, 200 M | 0.0895, 574 M | 0.1813, 1,363 M | 0.3672, 2,961 M | 0.7437, 6,198 M |
| N2 (USD 150 M, 2026 quotes) | 0.1195, 500 M | 0.2237, 1,436 M | 0.4532, 3,408 M | 0.9179, 7,403 M | 1.8592, 15,495 M |
| A16 / A14 (USD 250 M, extrapolated) | 0.1992, 833 M | 0.3729, 2,393 M | 0.7553, 5,680 M | 1.5298, 12,339 M | 3.0987, 25,825 M |
Reading. The stored-dataset chip without a shadow core pays at a USD 17 M market cap in the first two years, because its project is a 28 nm controller (chip-model-v3 5.6) and the chip's hour costs 56x less than rented hash. The class v4 shadow core forces an N5-class die (30 mm^2 at N = 100,000, lane 7) and lifts the bar 6x to USD 100 M. The glide lifts every bar about 2.3x per two years, so by years 9 to 10 the same N5 chip needs a USD 3.1 B cap. Nothing here needs N2 or A16: the chip is memory, and a leading node buys it nothing. So the "ASIC maker's economics at every node" collapses to two nodes, 28 nm and N5, and the N ladder is what moves between them.
Minimum volume to break even against buying cards (saving USD 2,131 a chip over two years against 5090s at the same hash, model): 28 nm bare 2,346 chips (0.39 TH/s); 28 nm + N5 shadow 14,077 chips (2.34 TH/s); N3 28,155 (4.67 TH/s); N2 70,387 (11.7 TH/s); A14 117,312 (19.5 TH/s). Against the rental-equilibrium hash (39 to 780 GH/s at today's three price inputs) the 2.34 TH/s break-even fleet is 3x to 60x the whole network: the chip only pays once the price is high enough for the network to be a few TH/s, which is the p* column above said another way.
### 2.3 The memory-controller chip against HBM4, per joule and per dollar, 2026 to 2036
| Year | Memory the chip buys | Chip uJ per hash at N = 100,000, k = 1 (approximate) | Honest 5090-class uJ | Edge per joule | Chip USD per MH/s | What moves it |
|---|---|---|---|---|---|---|
| 2026 | GDDR7, 16 x 2 GB | 1.37 | 3.27 | 2.4x | 2.8 | the measured row (algorithm.md 5.3a: 2.1x at the 5090's 431 W cap) |
| 2028 | HBM4, one stack 36 GB, C-HBM4E base die as the controller | 1.33 (algorithm lane's correction of lane 7's 1.11) | 3.3 (a 2028 card at the same read rate) | 2.5x | 2.0 to 2.5 (the interposer and controller rows fall into the base die; approximate) | HBM4 price USD 550 a stack falls as HBM4E takes the premium (approximate) |
| 2031 | HBM4E or HBM5 (SK hynix lists HBM5 on the 2029 to 2031 window) | 1.2 to 1.3 at the same N; 0.9 at N = 100,000 if activates per channel double again | 3.0 to 3.3 | 2.5x to 3.5x | 1.5 to 2.0 | activate parallelism per stack; unsourced beyond HBM4 |
| 2036 | the same class | the per-joule edge is bounded below by N x 11 pJ x k, so at N = 330,000 and k = 1 the chip pays 3.6 uJ of program work whatever its memory | 5.0 at 330,000 (the 5090 is compute-bound there) | 1.3x | 1.5 | N and k only |
Does the chip get cheaper or dearer per joule as HBM prices fall: dearer in dollars relative to the GPU through 2027 (lane 7 2.2, memory is 70 percent of its bill), cheaper from 2028 when the base die absorbs the controller, and flat per joule, because per joule is set by activates and by N. Per tier: the home 5090 owner stays inside 2.1x to 2.5x of the chip at N = 100,000 through 2031 and inside 1.3x at N = 330,000; the 4070-class 12 GB owner the same within 10 percent; the AMD 9070 XT owner sits at 5x to 8x behind the chip at every rung (its measured 10.6 uJ) and is the first tier a chip displaces; the Apple tier sits under the chip's per-joule line at every rung. The rig owner is a 5090 owner times eight. The pool user inherits the pool's card mix.
### 2.4 The FPGA route
AWS F2 (f2.6xlarge, VU47P, 16 GB HBM2, USD 1.98 an hour on demand, USD 0.66 spot) is the measurement the algorithm lane planned (algorithm.md 5.1); nothing has run. The tightened range stands: 2.3 to 2.9 G reads a second a card, 0.30x to 0.47x of the 5090 per watt, at USD 4,000 to 5,000 a card (approximate). Versal HBM and Agilex 7 M-series carry HBM2e (faster pins, the same tFAW), so they sit in the same row. An HBM4-based FPGA (none announced) would carry HBM4's channel count and the 0.3x to 0.5x row would become 0.6x to 1.0x (approximate, derived). Verdict: no FPGA displaces any tier to 2031; the F2 hour should still run, because the per-stack activate rate it measures is the input every row above rests on.
Recommendation for section 2: (1) the N ladder at genesis, as lane 2 and lane 7 said, with the bind-point re-measurement duty of 1.3; (2) write the p* table into the public threat model with the sentence "a stored-dataset chip pays at about USD 100 M of market cap in year 1 and about USD 700 M in year 5 (model, approximate)"; (3) no genesis parameter changes for N2 or A16, because the chip never needs them.
## 3. AI compute demand and the GPU supply
### 3.1 The numbers
| Row | Value | Source | Label |
|---|---|---|---|
| Datacentre GPUs shipped 2023 | 3.85 M units (NVIDIA 3.76 M, AMD 0.5 M, Intel 0.4 M) | TechInsights via HPCwire, 10 Jun 2024 | cited |
| Datacentre GPUs 2024, 2025 | USD 123 B of GPUs and accelerators in 2024, USD 207 B in 2025 (Omdia); NVIDIA estimated 5.2 M Blackwell GPUs in 2025; GB200 cabinet forecasts cut to 25,000 to 35,000 (2.5 M GPUs) | Omdia Aug 2025; Tom's Hardware | cited, unit counts secondary |
| Installed datacentre fleet by end-2026 | 15 to 20 M Hopper and Blackwell class units (sum of the rows above) | arithmetic | approximate |
| Consumer AIB shipments | Q2 2026 12.5 M units, +10 percent QoQ, +6.6 percent YoY; H1 2026 24.3 M; NVIDIA about 90 percent | Jon Peddie Research Q2 2026 | cited |
| Used H100 | USD 18,000 to 22,000 in 2026; residual 40 to 75 percent at 36 months, 25 to 35 percent at 60+ months; A100 80 GB USD 12,000 to 18,000 | mercatus-ai.com (verified 23 Jun 2026); intuitionlabs | cited, secondary |
| H100 rental | USD 1.49 (Vast.ai hosts) to 6.98 an hour; was over USD 7 in early 2024; spot about USD 1.00 | cloudzero; spheron; shattered.io (2026) | cited |
| Consumer card rental | 5090 USD 0.21 to 0.44 an hour (Vast.ai, 6 Oct 2026); 4090 0.28 to 0.60 | lane 7 2.4 | cited |
| Igneum hash rental | USD 0.0117 per MH/s-hour (RunPod community pods, 38 pods, 1,748 MH/s for USD 20.44 an hour); 8x 4090 rig USD 0.0129; a 5090 pod 98 to 128 MH/s for USD 0.41 to 0.74 | bench-log, 6 Oct 2026 | measured |
### 3.2 The used-GPU flood, 2027 to 2030
Hopper fleets bought in 2023 to 2024 reach the 36-month residual cliff in 2026 to 2027 and the 60-month floor in 2028 to 2029. Can they mine Igneum: the hash is memory-latency-bound, so an H100 is its five HBM3 stacks (80 GB) and an A100 its five HBM2e stacks. At chip-model-v3's unmeasured HBM3 ceiling (10.7 G reads a second a stack) an H100 reads 53 G, 3x a 5090; at the JEDEC tFAW ceiling (2.3 G a stack) 11.5 G, 0.65x. Nobody has measured it; the fleet measured A4000, A5000, L4, 3090 and 4090 (prover-tiers-real-cards.md), not an HBM part. The honest statement: an H100 mines Igneum at 0.65x to 3x of a 5090 at 700 W, which is 0.3x to 1.4x per watt (approximate, both ends unmeasured).
| Scenario | Hash it adds | Against the rental equilibrium (39 to 780 GH/s) | What the ladder does |
|---|---|---|---|
| 1 percent of a 1 M retired H100 fleet (10,000 cards) at 1x a 5090 | 1.3 TH/s | 2x to 35x the whole network | nothing: the shadow binds compute, and an H100 has 4x a 5090's ALUs per read; it holds every rung |
| 10 percent | 13 TH/s | 17x to 330x | the same |
| Rental at USD 1.49 an hour for 0.65x to 3x of a 5090 | USD 0.0045 to 0.021 per MH/s-hour | at or above today's 0.0117: no cheaper than consumer pods at list price | n/a |
| Idle-time rental (the owner's marginal cost is power) | USD 0.00016 to 0.0007 per MH/s-hour at USD 0.05 per kWh | 17x to 70x under today's rent | n/a |
The ladder is a joule argument against a fixed-datapath chip; against a GPU with more ALUs it is silent. The used-fleet question is a price question only.
### 3.3 The ten-year rental curve and the 51 percent table
The H100 rate fell about 45 percent a year from early 2024 to 2026 (USD 7+ to about 2); consumer-card rent fell as purchase prices rose (lane 7 2.4). Three curves for USD per MH/s-hour from today's 0.0117 (model):
| Year | At -20 percent a year | At -30 percent a year | At -45 percent a year |
|---|---|---|---|
| 2028 | 0.0075 | 0.0057 | 0.0035 |
| 2031 | 0.0038 | 0.0020 | 0.0006 |
| 2036 | 0.0013 | 0.0003 | 0.00003 |
What it does to `51-percent.md`: nothing to the dollar cost of any attack, because every row there is priced at the rental equilibrium, where rent equals subsidy. A cheaper rent means more hash joins until rent equals subsidy again: at 2036's -30 percent curve the equilibrium hash is 35x today's at the same IGN price, and the attack costs the same twelve days of emission. What the curve changes is the home card's share of the subsidy, which falls 35x with the hash, and the supply ceiling of the rental market, which stays the real limit (the market gave zero pods when asked for twenty, bench-log). Update the 51-percent price basis each year from a measured rental, not from a curve.
### 3.4 Per tier: does a home card stay competitive against an idle datacentre card
Cost per MH/s-hour, electricity only, a 5090-class card at 3.27 uJ (model):
| Owner and power price | USD per MH/s-hour | Margin under today's 0.0117 rent | Margin if idle datacentre hash sets the rent (0.00016) |
|---|---|---|---|
| UK home, 26.32 p (Ofgem cap, Q4 2026) | 0.00114 | 10x | loses 7x |
| Germany home, EUR 0.387 | 0.00137 | 9x | loses 9x |
| US home, 17.7 c (EIA, H2 2025) | 0.00058 | 20x | loses 4x |
| Texas industrial, 5 c (approximate) | 0.00016 | 72x | break-even |
| Paraguay, 4.4 to 6 c (ANDE crypto tariff, Decree 7824/2022, contracts end 31 Dec 2027) | 0.00016 | 72x | break-even |
| Iran, licensed, about 1 c | 0.00003 | 358x | wins |
The home card is competitive while the marginal supplier of hash is a rented consumer pod at list price (today). It is not competitive the day the marginal supplier is an idle datacentre card on industrial power, and the used-fleet flood of 3.2 makes that day a price event, not a technology event. Per tier: 8 and 12 GB home cards lose first (their uJ is 1.3 to 1.7x worse than the 5090's); 24 and 32 GB cards last; a rig is a home card eight times, on the same power price; a pool user's payout tracks the pool's share, which falls with the home share; Windows and Linux are the same; macOS at 0.78 uJ (M5 Max) holds a 4x power edge over the 5090 and loses last of all the home tiers; NVIDIA and AMD as their uJ rows (algorithm.md 5.3a); Apple as macOS.
What Igneum should do: the reward rule that prices rented hash out (lane 7's 3.1, weight-aged keys paid more) is the only lever in the protocol; the earnings page should show the miner's own cost per MH/s-hour against the network's implied rent, so a UK miner sees the day the line crosses; and the H100 and A100 random-read rate should be measured on one rented card this month (two hours, under the measure lock), because every row of 3.2 rests on it.
## 4. Energy, heat and the home
### 4.1 Prices and forecasts
| Region | Household price 2026 | Ten-year direction | Source |
|---|---|---|---|
| UK | 26.11 p per kWh (Jul to Sep 2026 cap), 26.32 p (Oct to Dec 2026) | Cornwall Insight's wholesale path falls to GBP 83 per MWh by 2029 ("over GBP 40 above historic"); retail scenarios 22 to 42 p by 2030 | Ofgem; Cornwall Insight (Jan 2024); solarpanelsforfactories (secondary) |
| EU | EUR 28.96 per 100 kWh average H2 2025; Ireland 40.42, Germany 38.69, Belgium 34.99; Hungary 10.82, Malta 12.82, Bulgaria 13.55 | The Commission's Electrification Action Plan (17 Jul 2026) targets electricity at most 2.5x gas for households by 2030 | Eurostat 5 May 2026; Commission |
| US | 17.7 c average H2 2025; "continue steady increase" | AEO2025 reference: 13 c (2024, a different basis) to over 20 c by 2050 | EIA |
| Cheapest mining regions | Iran about 1 c (licensed); Ethiopia 2 to 5.3 c; Paraguay 4.4 to 6 c; Kazakhstan about 4 c; Nigeria 4.8 c hosted | spark.money; oneminers; hashrateindex Paraguay (4 May 2026) | secondary |
### 4.2 Home mining as heating
| Product or trial | Facts | Source |
|---|---|---|
| Heatbit Trio, Maxi, Maxi Pro | USD 849 (10 TH/s, 400 W mining + 1,100 W resistive) to USD 1,499 (60 TH/s, 1,500 W); seasonal BTC USD 300 to 420 (Heatbit's own figure); Wired's review: mining covers 30 to 40 percent of electricity at 12 to 15 c per kWh | miningboard.com; techbuzz (5 Apr 2026) |
| 21energy, MintGreen, HotMine | convector radiators 250 to 2,700 W; hydronic boilers for radiators and hot water | miningboard.com |
| Qarnot "radiateur numerique" | 100 RIVP social-housing flats in Paris 15e heated by compute radiators from 2013; Qarnot moved to boilers; the model is "the building pays the capital, heat is free" | fr.wikipedia Qarnot; maisonapart |
The economics per kWh (model): a 5090 at the 431 W cap is a 0.43 kW heater. Credit the heat at the gas price delivered through a 90 percent boiler, or at a heat pump's electricity (COP 3):
| Region | Electricity | Heat credit, gas | Heat credit, heat pump | Effective price in the heating season |
|---|---|---|---|---|
| UK | 26.3 p | 7.0 p (27 percent) | 8.8 p (33 percent) | 17.5 to 19.3 p |
| Germany | 38.7 c | 13.3 c (34 percent) | 12.9 c (33 percent) | 25.4 to 25.8 c |
| US | 17.7 c | 5.6 c (31 percent) | 5.9 c (33 percent) | 11.8 to 12.1 c |
A third off the power bill for the 1,500 to 2,000 heating hours a year (approximate), everywhere. It moves a UK home miner from 7x to 5x the Texas industrial price, not to parity. Consequence per tier: it matters most to the tiers with the worst uJ (8 and 12 GB, AMD) and least to Apple (21 W is not a heater). Recommendation: a heat mode in Ember (run the miner only while a room thermostat or schedule calls, power cap set to the room's load, the hourly program unchanged), which costs nothing in protocol and is the one feature home-mining heaters ship.
### 4.3 Grid balancing
ERCOT paid Riot USD 31.7 M in August 2023 (24.2 M curtailment credits plus 7.4 M demand response) and Riot booked USD 30.6 M of power-curtailment credits in Q3 2025, up 147 percent on the year (ABC13; Riot releases). The programmes name "large flexible customers"; a home GPU is not one. Home aggregators exist (the UK's supplier demand-flexibility sessions, US utility programmes; approximate, from memory) and pay per kWh shed against a baseline. A fleet of Ember miners is a shed-able load only if a signal reaches it. Recommendation: a curtailment input in Ember (a webhook, a schedule, a price threshold from a public spot feed) that pauses the miner and resumes it; the protocol sees a key that stops voting for an hour, which the LEAVE item of 0.3.16 already prices as nothing (vote-or-burn.md: no burn). Per tier: a pool user's pool must pass the signal down; a rig is the only home tier big enough to enrol directly.
### 4.4 The rules by region
| Region | Rule | Source | What it means for an Igneum home miner | What Igneum builds |
|---|---|---|---|---|
| EU, MiCA | White papers must state the consensus mechanism's climate impacts; CASPs must publish the sustainability indicators per asset (Delegated Regulation (EU) 2025/422; mandatory kWh a year, more above 500,000 kWh); Article 142 report on environmental impact and "minimum sustainability standards"; the 2022 Parliament vote dropped a PoW ban; the 2026 MiCA review consultation (reply by 31 Aug 2026) asks only how appropriate the disclosure regime is (Q53) and nothing on PoW | MiCA; 2025/422; the consultation PDF (fetched) | nothing on the miner; the exchanges that list IGN need the kWh figure | publish Igneum's own 2025/422-format indicators from the hash-rate and the measured uJ, updated each era |
| Norway | ban on new PoW mining data centres from autumn 2025; data-centre registry; existing sites run | CoinDesk 23 Jun 2025 | home mining untouched; no new hosting | nothing |
| Sweden | data-centre electricity tax relief removed July 2023 (SEK 0.006 to 0.36 per kWh); SEK 500 M of back-tax on nine firms 2024 to 2026 | CoinDesk 14 Apr 2023; crypto.news | home miners already paid full tax; hosting is dead | nothing |
| Russia | mining banned in 10 regions 1 Jan 2025 to 15 Mar 2031; Moscow region from 15 Aug 2026 to 2032; seasonal bans in Irkutsk, Buryatia, Zabaikalsky; no new regions in 2026 | TASS; Cryptopolitan | a region check at install; the 2024 law's 6,000 kWh a month household allowance (approximate, from memory) covers one card | a region prompt in Ember with the banned list |
| Kazakhstan | mining legal outside the AIFC (Nov 2025 law); "strategic mining" rules from 1 Aug 2026 with a share to the national reserve | Caspian News; KuCoin | licensed industrial; a home card is below any threshold found | nothing |
| Paraguay | ANDE crypto tariff USD 44.33 per MWh (Decree 7824/2022), lifted toward 5.1 to 6 c; every crypto contract ends 31 Dec 2027 | hashrateindex 4 May 2026 | the cheapest hydro region closes to new load in 2028 | nothing |
| Iran | licensed mining at a mining tariff; seasonal shutdowns in power shortages (approximate) | ainfp.org; MEXC | the cheapest power on earth and the least reliable | nothing |
| China | illegal; joint Notice 6 Feb 2026 reaffirmed; one report of Sichuan, Inner Mongolia, Xinjiang reopening from 1 Jan 2026 is uncorroborated | lightspark; egw.news (single source) | a Chinese home miner runs at legal risk | the region prompt |
| US, federal | SEC staff statement 20 Mar 2025: PoW mining, solo and pooled, is not a securities offering; DAME 30 percent excise proposed 2023, 2024, 2025 budgets, never enacted; EIA's emergency survey (Jan 2024) blocked in court (Mar 2024); CLARITY failed cloture 49 to 50 on 15 Sep 2026; GENIUS Act (stablecoins) 2025 | Dechert; Blockworks; Fortune; Orrick 2 Oct 2026 | nothing on the miner | nothing |
| US, states | Texas, Kentucky, Wyoming pro; New York's fossil-PoW moratorium (2022, approximate); California's DFAL licensing from 1 Jul 2026 reaches crypto businesses, not a home card | sazmining; crypto.news | a home miner is not a licensee anywhere found | the region prompt |
Per-region electricity-price prompt: the earnings page should default the price per kWh from a public table by country (the Eurostat, Ofgem and EIA rows above), let the miner edit it, and show the miner's own break-even hash share, because the number that ends a home miner is the bill, not the regulation.
## 5. Zero-knowledge proving cost, 2026 to 2036
### 5.1 The numbers today
| Row | Value | Source | Label |
|---|---|---|---|
| EF real-time proving target (10 Jul 2025) | P99 under 10 s, capex under USD 100 K, under 10 kW, open source, 128 bits (100 accepted at first), proof under 300 KiB, no trusted setup; written for solo stakers "from home" on a 10 kW supply | blog.ethereum.org | cited |
| Ethproofs 2025 review (6 Dec 2025) | USD 1.69 to under a penny a proof in nine months; 7 zkVMs, 15 provers, about 200,000 blocks; four teams at sub-10 s P99; single-GPU proving from 16 min to under 60 s; 2026 target sub-8 s P99 and kWh a proof as the metric | hackmd willcorcoran | cited |
| SP1 Hypercube | 99.7 percent of blocks under 12 s on 16 x RTX 5090, cluster under USD 100 K; about USD 0.02 a block single-node | Succinct blog; The Block | cited |
| Pico Prism | 99.9 percent under 12 s on 64 x 5090 | Brevis | cited |
| Cysic Venus | 7.4 s a block on 24 GPUs (type unstated); ZK ASIC claims (1.33 M Keccak a second, 50x energy) with no shipping date | bex.co 17 Apr 2026 | cited, ASIC unverified |
| ZisK | p99 9.62 s on 4 x 5090 | GitHub comparative analysis, Sep 2026 | secondary |
| Airbender | 51 s average on one RTX 4090, under a cent | bex.co Jan 2026 | secondary |
| RISC Zero | R0VM 2.0: 35 min to 44 s a block (Dec 2025) | wavect; RISC Zero blog | secondary |
| Jolt | Lattice Jolt (9 Sep 2026): 2 to 3x faster, 65 to 80 KB proofs, 2 M cycles a second CPU, over 10 M with a GPU, post-quantum | cryptobriefing | cited |
| Cost a block on the tracker | about USD 0.005 (Sep 2026) | lane 7 2.6 | secondary |
| Hardware provers | Cysic (C1, ZK-Air, ZK-Pro), Fabric (VPU), Ingonyama (ICICLE; Accseal Leo ASIC in ICICLE v3), Irreducible (FPGA clusters, Binius), Supranational; "10 to 100x on MSM and NTT" claims | h33.ai survey; Ingonyama; Cysic docs | claims, no shipped benchmark on a zkVM block |
| Igneum's own | 11 rented cards: shard beside the miner 10.7 s (5090) to 37.5 s (3060); alone 4.8 to 18.4 s; SP1 compressed verify 0.032 s on a Mac core | prover-tiers-real-cards.md; bench-log 5 Oct | measured |
### 5.2 The trend line to 2036 and the 20 percent pool
Lane 7's 33x a year is software catching hardware and cannot hold. Hardware alone is 1.5x a year. The EF's own 2026 metric is kWh a proof, which is the right axis for a miner-prover: a shard that costs a joule of GPU time is paid from the pool and competes with the same joule in the lottery.
| Year | Block proof cost on the open market (USD, approximate) | Hardware that proves an Ethereum block in real time | What proves an Igneum shard (4.7 M cycles) under 10 s | Does a home 12 GB card have a place |
|---|---|---|---|---|
| 2026 | 0.005 to 0.02 | 16 x 5090 (SP1), 4 x 5090 (ZisK) | 5090 beside its miner (10.7 s), every card alone | yes, alone or hand-off (prover-tiers-real-cards.md) |
| 2028 | 0.001 to 0.005 | 1 to 4 consumer cards; first ASIC or VPU boards if any ship (none has) | every card from the 3060 at 3x a year (lane 7's table); 12 GB beside the miner at 3x, not at 1.5x | yes alone; beside the miner only under 3x |
| 2031 | 0.0003 to 0.001 | one consumer card, or a prover ASIC at 10 to 50x per joule if the claims land | a 12 GB card in 1 to 3 s | yes, but a prover ASIC would take the external job market first (dollar-priced jobs go to the cheapest joule), and the pool second only if shards are open to anyone |
| 2036 | under 0.0001 | commodity | any card | the pool's economics are the lottery's: whoever holds vote weight is drawn (sortition by weight), so the home card keeps its share of the pool whatever an ASIC does to the open market |
The design's defence is already in place: the pool is drawn by vote weight (sortition), and vote weight is 30 days of blocks, which a prover ASIC does not have. A prover ASIC centralises the external job market, not the pool. What it would do to the pool is set the shard deadline: if the chain tightens the deadline toward ASIC times, home cards miss it. So the shard deadline must be a function of the measured fleet median (lane 7's rule), re-read each era, and the shard size must stay at a size a 12 GB card proves alone inside it (today 4.8 to 14.4 s). "Verified proving as the reward" (horizon-2026-10 item 1: the proof verified in consensus) is the piece that makes the pool unforgeable, and its activation is the decision owed.
Per tier: 8 GB (proves alone, never beside its miner; keeps its pool share by weight); 12 GB (the swing tier; the hand-off profile is the product); 16 GB and up (unconstrained); rig (proves beside mining on every card from 2028 at 1.5x); pool user (the pool operator's prover does it); Windows, Linux (the same); macOS (an M5 Max proves a shard, unmeasured against the rented table; Metal lane open); NVIDIA (every measurement is NVIDIA); AMD (no measured shard time; the 9070 XT has no SP1 GPU backend measured here, so the AMD tier proves on CPU or not at all until it is measured, which is the first owed number); Apple (as macOS).
### 5.3 Proof-system risk and the swap interface
| Event | Date | What a malicious prover could do | Source |
|---|---|---|---|
| SP1 v3.4.0 (LambdaClass, 3MI, Aligned) | disclosed 26 Jan 2025 | "generate valid SP1 proofs of incorrect execution of an arbitrary program": universal forgery, from two bugs plus a Plonky3 evaluation gap | LambdaClass blog; Blockworks |
| RISC Zero zkVM 2.0.0 to 2.0.2 | 15 May 2025 | a missing constraint in the rv32im circuit let any 3-register instruction be proven wrong; on-chain verifiers stopped by estop | HackenProof |
| SP1 Hypercube JALR | 20 May 2026 | a completeness bug (prover crash), not soundness; the EF's audit found only 51 of 62 opcodes fully proven, four load instructions proven against wrong specifications | zkevm.ethereum.foundation |
Three soundness-class events in 18 months across the two leading zkVMs. On Igneum today a soundness bug is a light-client problem (spec 10.1; finality-in-proof.md 4.4): every full node executes natively and vetoes a record whose statement differs. It becomes a chain failure the day any of three things is true: (1) proof verification in consensus pays a shard on the proof alone (the 0.3.16 switch) and a forged proof carries a correct statement, which earns the pool and nothing else; (2) finality is carried inside the proof (lane 7's 3.3) and a forged proof carries a forged weight table, which a full node still vetoes, so the failure is confined to proof-only clients; (3) the chain ever lets a proof replace execution for full nodes, which the design forbids. So the chain-failure case is (3), and the rule is: never. The swap interface needs: a pinned verifier key per proof system with a version in the record; two independent zkVMs accepted in parallel (the EF's own "multiple provers" lesson), with a record valid only if its system is on the active list; a 95 percent class-change signal to retire a system, and a stop switch (RISC Zero's estop pattern) that any 1/3 of weight can flip to "execution only" inside an hour. Per tier: nothing a miner does; a pool's prover must build for two systems; the cost is two guest builds and two verifier keys.
## 6. Light clients on phones, 2026 to 2036
### 6.1 The state of the art
| Client | What it verifies | Bytes and time | Source |
|---|---|---|---|
| Ethereum sync-committee clients (Helios, Kevlar) | 512-validator sync committee signatures; syncs in about 2 s, no storage; "lightweight enough to run on mobile" | about 25 KB per two days (24,576 bytes of keys plus the signature, header and branch) | a16z Helios; annotated spec |
| Mina | a recursive SNARK of the whole chain | a 22 KB chain; "a few milliseconds of processing" | Mina docs via gate.com, iq.wiki |
| Celestia Lumina | data-availability sampling in a browser or phone (Wasm, Rust) | random shares a block; bandwidth not published for 2026 (approximate: tens of MB a day) | celestiaorg/lumina; Eiger |
| Bitcoin BIP-157/158 (Neutrino: Breez, Blixt) | compact block filters served by full nodes | headers and filters in under 5 minutes | Blixt; Lightning Labs |
| StarkWare's Bitcoin header proof | every header since genesis in one STARK | 1 MB, under 100 ms on a phone | cryptotimes 11 Sep 2025 |
| Zcash (Zashi/Zodl SDKs, lightwalletd; Tachyon-Lite) | shielded sync through servers | server-dependent (the anti-pattern) | Zcash forum, GitHub |
| Kaspa wallets (Kaspium, kaspa-core) | none: wallets talk to public nodes over wRPC | n/a (approximate) | coincodex; Zelcore |
| Phone verify times | Groth16 about 5 ms; a Keccak circuit's verify 0.12 s on an iPhone 15 Pro (Mopro); a 45 KB STARK in 16 ms (laptop, approximate); Groth16 proving 2.9 to 3.1 s on a Galaxy S25 and iPhone 17 Pro | Mopro benchmarks; provebench; shattered.io | cited, mixed devices |
| WebGPU | in Chrome 113, Edge 113, Safari 18, Firefox 141 | n/a | Wikipedia WebGPU |
### 6.2 What Igneum's finality-in-proof needs from the phone
The client holds one proof and fetches the newest segment proof from any node (finality-in-proof.md 4.2); SP1's compressed verify is 0.032 s on a Mac core (bench-log 5 Oct), a Groth16 or Plonk wrapper is unmeasured. Model (a wallet updating every 10 minutes, 144 times a day, a phone big core at 3 W, LTE at about 1.5 J a MB, an 18 Wh battery):
| Form the wallet verifies | Bytes a day | CPU | Radio | Battery a day |
|---|---|---|---|---|
| Groth16 or Plonk wrapper (about 1 KB with public values) at about 10 ms on a phone (approximate, 3x the Mac core) | 0.14 MB | 4 J | under 1 J | 0.007 percent |
| Compressed STARK at the EF's 300 KiB ceiling, about 100 ms on a phone | 42 MB | 43 J | 63 J | 0.16 percent |
Either is nothing. The choice is the EF's: no trusted setup and under 300 KiB, which is the STARK row, and by 2030 a WASM-SIMD or WebGPU verifier on a phone should put the STARK verify under 30 ms (approximate projection from the 294x STARK-verifier speedup reported in 2026 and the WebGPU adoption row). The 2026 answer is the Plonk wrapper (no trusted setup, small) for the phone and the compressed STARK for nodes. Bytes a day are set by update frequency, and a wallet that updates on open rather than on a timer is under 1 MB a day in either form.
"Every miner is also a light-client server" has prior art: Bitcoin full nodes serving BIP-157 filters under the NODE_COMPACT_FILTERS service bit (every full node that opts in serves every light client), and Ethereum's Portal Network (every node serves a slice; "without having to trust or put extra strain on full nodes"). The anti-pattern is Zcash's lightwalletd, a few servers everyone trusts. Recommendation: the node serves `igneum_getSegmentProofBytes` over p2p and a rate-limited HTTP path, on by default in Ember, so the serving set is the miner set; the phone client dials three miners and takes the longest valid chain of proofs. Per tier: no cost a miner notices (one proof of a few hundred KB served on request); the pool node serves for its members; Windows, Linux, macOS, every vendor the same.
## 7. Post-quantum signatures and a proof-of-work chain
### 7.1 The standards and sizes
| Scheme | Standard | Public key | Signature | Status | Source |
|---|---|---|---|---|---|
| ML-DSA-44 | FIPS 204 | 1,312 B | 2,420 B | final (Aug 2024) | Cloudflare 9 Jul 2026; FIPS 204 |
| ML-DSA-65 | FIPS 204 | 1,952 B | 3,309 B | final | encryptionconsulting |
| ML-DSA-87 | FIPS 204 | 2,592 B | 4,627 B | final | same |
| SLH-DSA-SHA2-128s / 128f | FIPS 205 | 32 B | 7,856 B / 17,088 B | final | Cloudflare |
| FN-DSA-512 (Falcon) | FIPS 206 | 897 B | 666 B | draft; final expected late 2026 to early 2027; floating-point signing is "difficult to implement securely" | encryptionconsulting; Cloudflare |
| ML-KEM | FIPS 203 | n/a | n/a | final | NIST |
| BLS12-381 (today) | n/a | 48 B | 48 B aggregate for 8,192 voters | quantum-broken by Shor on the curve's discrete log | ethereum.org PQ page |
Timelines: NIST IR 8547 deprecates ECDSA, EdDSA, RSA and EC Diffie-Hellman after 2030 and disallows them after 2035 (final version confirmed). The Global Risk Institute's 2025 survey (26 experts, report page dated 9 Mar 2026): a cryptographically relevant quantum computer "quite possible (28 to 49 percent)" within 10 years and "likely (51 to 70 percent)" within 15. Resource estimates: ECC-256 at 1,200 to 1,450 logical qubits and 70 to 90 M Toffoli (Google, 2026), about 500,000 physical qubits against about 1 M for RSA-2048 (Gidney, May 2025); 835 logical qubits with 2^30.6 Toffoli (Luo et al., arXiv 2607.13816, Jul 2026). Bitcoin: BIP-360 merged into the BIPs repository 11 Feb 2026 as a draft (P2MR, formerly P2QRH), a companion BIP for ML-DSA and SLH-DSA, a testnet implementation March 2026, no activation. Ethereum: a PQ team formed January 2026; BLS to be replaced by leanXMSS (hash-based) with leanVM aggregating "3,000 bytes" of signature against BLS's 96 by "250x"; core PQ infrastructure targeted "by approximately 2029"; EIP-8141 account abstraction for user migration.
### 7.2 What quantum does to Igneum
| Component | Break | Consequence | Size of the fix |
|---|---|---|---|
| BLS vote keys (in every header) | Shor on BLS12-381's G1 discrete log (a 255-bit subgroup over a 381-bit field; wider than secp256k1, so a later break by a year or two, approximate) | every vote key is public; a CRQC forges two thirds of weight and certifies any chain. Catastrophic | the migration below |
| Hash-to-curve | none; it is a hash | nothing | nothing |
| ECDSA accounts in the EVM | as Ethereum: exposed public keys after a first spend | user funds; the same exposure as Ethereum's "0.1 percent dormant" row, smaller | account abstraction with an ML-DSA verify precompile from genesis |
| The VRF (aggregator pick) | if EC-based, forgeable; aggregation is not safety (every voter signs) | liveness nuisance | the same key succession |
| The class-group VDF (epoch seed, era draw) | Shor computes the class-group order, which removes the sequentiality assumption of a Wesolowski-style VDF (approximate; from memory of the class-group VDF literature) | an attacker with a CRQC grinds the hourly program seed | a hash-chain fallback behind the same version byte; flagged, not sized |
| SP1 (STARK core, Groth16/Plonk wrapper) | the STARK is hash-based and stands; the pairing wrapper falls | the on-chain and phone verifier moves to the compressed STARK | the wrapper choice of section 6 |
### 7.3 The cost in bytes, 8,192 voters, every voter signing every 30-second checkpoint (model)
| Scheme | Per checkpoint | Per day (2,880 checkpoints) | Averaged per block at 1 block/s | Key in the header |
|---|---|---|---|---|
| BLS aggregate (today) | 1.0 KB (48 B + a 1,024 B bitmap) | 2.9 MB | 34 B | 48 B |
| ML-DSA-44 | 19,361 KB | 57.1 GB | 645 KB | 1,312 B |
| ML-DSA-65 | 26,473 KB | 78.1 GB | 882 KB | 1,952 B |
| FN-DSA-512 | 5,329 KB | 15.7 GB | 178 KB | 897 B |
| SLH-DSA-128s | 62,849 KB | 185 GB | 2,095 KB | 32 B |
| SLH-DSA-128f | 136,705 KB | 403 GB | 4,557 KB | 32 B |
| ML-DSA-44 aggregated by a SNARK at the EF's 250x | 77 KB | 223 MB | 2.6 KB | 1,312 B, or a 32 B hash of it |
A naive ML-DSA swap costs 57 GB a day of votes against a block stream of about 100 MB a day (approximate), 500x. It is not shippable without aggregation. The aggregator already exists in the design (VRF picks 8 aggregators a checkpoint): the migration is "aggregators carry a STARK of N verified PQ signatures", which is Ethereum's leanVM shape, and the per-checkpoint cost falls to the order of 100 KB.
### 7.4 The plan to pre-commit at genesis
1. A `sig_scheme` version byte in the vote item and in the vote-key registration; genesis value 0 = BLS12-381.
2. Key succession at registration: every vote key registers with a 32-byte hash of a successor public key (any scheme). A `succeed` item signed by the old key and the new key moves the 30-day weight to the successor without a reset. Miners generate the successor at first run; Ember stores it offline.
3. A PQ verify precompile (ML-DSA-44 first, FN-DSA when FIPS 206 is final) in the EVM from genesis, so account abstraction can migrate users before 2030.
4. The flip is a class change: 95 percent signal with a floor height, as the P2 mechanism; the aggregated-vote format ships first, the scheme flip second.
5. The VDF carries the same version byte with a hash-chain fallback.
6. The public sentence: "Igneum's vote keys and accounts can move to NIST post-quantum signatures by miner signal; the key succession is in every key from genesis."
Per tier at migration: a home miner on any card runs the updater and signs one `succeed` item from Ember; ML-DSA-44 signing is well under a millisecond on any CPU (approximate), every 30 s; the bandwidth cost is the aggregated form's, about 100 KB a checkpoint, which an 8 GB card's host handles; a rig's one key succeeds once; a pool's key is the operator's, and pool members do nothing; Windows, Linux, macOS, NVIDIA, AMD, Apple: nothing hardware-specific, since the signature runs on the CPU.
## 8. Regulation of mining and of coins with no issuer, 2026 to 2036
### 8.1 The texts
| Regime | What it says | Source |
|---|---|---|
| MiCA Article 4(3) | Title II (offers and white papers) does not apply where the crypto-asset is "automatically created as a reward for the maintenance of the distributed ledger or the validation of transactions" (point (b)); where there is no identifiable issuer "the obligation to produce a white paper does not apply to an issuer, as none exists"; a CASP that plays an active or promotional role may have to draw up one (Article 5 and the trading-platform duty under Title V) | Osborne Clarke (4 Oct 2023); Conventus Law; Squire Patton Boggs |
| MiCA sustainability | Article 66 and Delegated Regulation 2025/422: CASPs publish the consensus mechanism's energy (kWh a year mandatory; more above 500,000 kWh); the Commission's Article 142 report may propose "minimum sustainability standards"; the 2026 review consultation (reply by 31 Aug 2026) asks only how appropriate the regime is (Q53) | the consultation PDF; carbon-ratings; Latham tracker |
| MiCA transition | over on 1 Jul 2026; unlicensed service to EU clients is a breach | ESMA statement Apr 2026 |
| UK | The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026: regulated activities from 25 Oct 2027 (issuing qualifying stablecoins, safeguarding, operating a qualifying cryptoasset trading platform, dealing, arranging, arranging staking); gateway and savings window 30 Sep 2026 to 28 Feb 2027; a "qualifying cryptoasset" is the FCA perimeter term (the formal definition sits in the Regulations and was not retrievable here); mining and validating are not in the activity list found; the 2023 financial-promotions regime already covers promotions of qualifying cryptoassets to UK consumers | FCA policy statements page; Lewis Silkin 30 Sep 2026; Skadden Jul 2026 |
| US | SEC Corporation Finance staff statement 20 Mar 2025: PoW mining, solo or pooled, is not an offer of securities (non-binding, facts and circumstances); CLARITY (CFTC over digital commodities) failed cloture 49 to 50 on 15 Sep 2026, a motion to reconsider preserved; GENIUS Act 2025 covers payment stablecoins; DAME 30 percent excise proposed three times, never enacted | Dechert; Orrick 2 Oct 2026; Cointelegraph |
| FATF | Recommendation 16 revised June 2025; implementation by end-2030; unhosted wallets still treated differently by country | FATF best practices Jun 2025; Sumsub |
| DIFC (Igneum Labs LTD's seat) | DFSA crypto-token regime amended 12 Jan 2026: firm-led suitability, no more Recognised Crypto Tokens list, controller approval at 30 and 50 percent; applies to firms providing financial services in crypto tokens; nothing on mining or software | Dechert 13 Jan 2026; Arabian Business |
| Dubai outside DIFC | VARA rulebook v2.1 (2026): exchange services, disclosures, token issuance; a federal licensing decision Feb 2026 | TradingView/Coinpedia; Dechert |
### 8.2 What it means for each actor
| Actor | EU | UK | US | DIFC | FATF |
|---|---|---|---|---|---|
| A pool operator paying members | not a CASP for mining; a CASP if it holds members' coins or exchanges them (custody, exchange); the energy figure is the CASPs' duty, not the pool's | not an activity listed, unless it safeguards or deals; from 25 Oct 2027 a pool that holds balances looks like safeguarding | SEC: pooled mining not a security; FinCEN money-transmitter guidance on pools is the open point (approximate) | not a financial service unless it custodies | a pool that holds and sends on behalf of members is a VASP-shaped entity by end-2030 |
| A home miner selling coins | a seller, not an offeror; taxed as income then gains (country rules) | the same; promotions rules do not reach a private sale | income at receipt (IRS), then gains | n/a | the exchange it sells on carries the travel rule |
| The entity publishing the software (Igneum Labs LTD) | no issuer under 4(3); the white paper is nobody's duty; publishing the 2025/422 indicators voluntarily lets CASPs list | not an activity; public text must not be a financial promotion of a qualifying cryptoasset to UK consumers (the 2023 regime), which rules out "buy", "invest" and price talk | the SEC statement covers mining, not the publisher; CLARITY's "mature blockchain" test is the thing to watch if it passes | a software company in the DIFC with no financial service and no token sale sits outside the DFSA token regime on its face | n/a |
| The testnet with no value | nothing; no asset | nothing | nothing | nothing | nothing |
| The external proving market paid in dollars | a job is a service; settlement in IGN on-chain with no operator custody is not a CASP activity; an operator that converts dollars to IGN is an exchange | the same; dealing or arranging if an operator sits between | money transmission if an operator holds funds | a dollar-settled service is a financial service only if the entity holds or exchanges | the same |
### 8.3 What Igneum writes into its genesis and public text now (not legal advice; counsel is engaged)
1. No issuer, no offeror, no sale: every coin is created as a block reward (MiCA Article 4(3)(b) language, verbatim in the litepaper).
2. The 2025/422 sustainability indicators (kWh a year from hash rate and measured uJ, intensity per transaction, mix by region when known) published by the project each era, so an EU CASP can list without asking.
3. No financial promotion: no price, no "buy", no "invest", no return language anywhere the UK can read it; the earnings page shows hash and IGN, not sterling.
4. The pool reference implementation never holds a member's balance: payouts are direct from the coinbase split (the pool is a coordinator, not a custodian), which keeps pools out of CASP, safeguarding and VASP shapes in every regime above.
5. The job market is peer-to-peer settled on-chain; no operator account, no dollar leg in the protocol; the dollar price is a quote, the settlement is IGN.
6. The software is published under an open licence by a company that holds no coins by right (no dev fund, already decided) and runs no service the chain depends on.
7. The region prompt and the banned-region list in Ember (Russia's ten regions and Moscow from 15 Aug 2026, China) with the sentence "mining may be restricted where you are; you are responsible for checking".
8. A genesis "no privileged key" statement: no key can mint, pause or upgrade (true by design; say it because the regulators' tests turn on it).
## 9. Ten-year scenario table
| Year | Scenario A: GPUs stay general and cheap | Scenario B: HBM-only high end, APU-only low end | Scenario C: proving ASICs win |
|---|---|---|---|
| 2028 | 48 GB flagship on GDDR7 (lane 7); used H100s at USD 7,500 to 10,500 flood rentals; hash at the rental equilibrium, home share falling with the rent curve. Igneum: the N ladder's first rung by signal; home miners inside 2.5x of the chip per joule; the chip pays at USD 100 M of cap. Alive. The parameter: N stepped by signal | HBM4 only on datacentre parts; consumer GDDR7 unchanged; APUs (Medusa Halo, M6) take the laptop tier. Igneum: nothing changes for the hash; the Apple and APU tiers grow. Alive. The parameter: the cache rung, in case an APU's LLC reaches 256 MB | First VPU or C1 boards ship at 10 to 50x per joule on MSM and NTT; the external job market goes to them within a year. Igneum: the 20 percent pool is sortition by weight, so home cards keep it; the dollar market is lost to ASICs. Alive, with the external income line (already "never the main income" by 2030, lane 7 3.11) gone sooner. The switch: the shard deadline as a function of the fleet median |
| 2031 | GDDR7-Next; 64 GB flagship; rental at 0.002 to 0.004 per MH/s-hour; hash 3 to 6x today's at the same price. The chip bar is USD 1.4 B at N5. Home miners on retail power are marginal unless the heat mode and the price prompt keep the UK and EU tiers on in winter. Alive; the home share is 10 to 20 percent (approximate). The parameter: the weight-aged reward rule (lane 7 3.1) | A consumer HBM4-class halo card appears (unannounced today): 2 to 4x the read rate of a 2026 card; the home 2026 cards fall to 0.25 to 0.5x of a new card, the GPU cadence twice over. The chip's stack-level edge is the same as the card's, so the per-joule gap closes to about 1.5x. Alive; the installed base shifts to the new card. The parameter: the N bind-point re-measurement per generation | Prover ASICs at 100x; the EF's L1 zkEVM runs on them; SP1-class software moves to ASIC backends. Igneum: proving in consensus verified, home cards prove shards inside the deadline because the deadline is the fleet's; the pool's 20 percent stays with weight. Alive. The risk: if a soundness bug in the ASIC's backend lands, the stop switch of 5.3 is the defence |
| 2036 | 96 GB cards; rent at 0.0003 to 0.0013; hash 10 to 35x; the emission at the 1 percent tail (86 M IGN a year). Security is 1 percent of market cap a year (tail-emission.md). Igneum lives if the cap is over about USD 50 M (a 24-hour attack at 0.032 percent of cap is USD 16,000 against a rental market that can supply it); dies below that only in the sense every PoW chain does: cheap to attack, nothing to steal. The parameter: the tail | HBM everywhere above the laptop; the f = 1 chip and the halo card are the same memory; the ASIC question is closed by parity and the ladder's N is the remaining difference. Alive. The parameter: N at the verifier's 10 ms ceiling | Every proof is an ASIC proof; the pool pays miners for shards an ASIC proves 100x cheaper; miners buy ASIC prover boards the way they buy cards (USD 500 to 2,000 boards, approximate guess). Igneum: proving is a second card, not a second income. Alive. The parameter: the shard deadline rule |
Where Igneum dies, honestly:
| Death | Scenario | What would be needed to survive it |
|---|---|---|
| The stored-dataset chip at N5 is built at a USD 100 M cap in year 1 and holds over a third of hash by year 2 | A, 2028, if the N ladder is not at genesis or the signal never steps it | the N ladder at genesis with its first rung live; the weight-aged reward; the honest sentence that the chip's bar is USD 100 M, so the cap passes it fast or not at all |
| Idle datacentre hash sets the rent and the home tier leaves; weight concentrates in three hosting firms; a hosting failure is a 30-day finality pause | A, 2031 | the LEAVE item (shipped), the reward rule that pays aged keys, the heat mode and price prompt that keep winter home miners on, and a public "weight by hosting provider" chart so the concentration is seen |
| A CRQC in 2033 to 2036 (28 to 49 percent inside ten years, GRI) before the key succession has flipped | any, 2033+ | the genesis key succession and the aggregated-vote format shipped by 2030, the flip signalled the year NIST deprecates (2030), not the year a machine appears |
| A soundness bug in the one proof system while the pool pays on the proof alone | C, any year | two zkVMs on the active list and the 1/3-weight stop switch |
| The cap never passes USD 20 M: the tail's 1 percent is USD 200,000 a year of security, a day's rental | all, any year | nothing in the protocol; it is the market's verdict, and the design should say so rather than promise a floor |
## 10. Verdict table
| Axis | Finding | Source | Per-tier consequence | Recommendation |
|---|---|---|---|---|
| Memory roadmap | tRC flat for about 20 years; HBM4 doubles channels a stack (2026); HBM4E adds pins and a custom base die (2027 to 2028); no consumer HBM, no GDDR8 before 2029 to 2031 | JEDEC, SK hynix roadmap, Lee et al. | a 2026 card keeps its read rate against a 2028 card; 8 and 12 GB leave the installed base by 2030, not the hash | nothing at genesis; re-measure the N rungs per generation (text, a measurement duty) |
| The cache | consumer LLC 96 to 128 MB; datacentre 256 MB today | chip-model-v3, MI300X (approximate) | an LLC at the cache size gives that card's owners a 2 to 3x shortcut | a cache-size rung on the signal ladder (genesis parameter) |
| The dataset | 2 GiB to 16 GiB over 28 years is under every card and never binds before year 12 | algorithm.md 5.6 | the prover footprint binds first | nothing; fix the public card-lifetime sentence (text) |
| The chip's bar | pays at USD 17 M of cap bare, USD 100 M with the N5 shadow core in years 1 to 2, 2.3x higher every two years with the glide; never needs N2 or A16 | model, siliconanalysts mask costs | the 9070 XT tier is displaced first, Apple never per joule, the 5090 inside 2.5x | the N ladder at genesis (parameter); the p* sentence in the threat model (text) |
| C-HBM4E | the memory controller moves under the stack from 2027 to 2028 | TSMC/GUC via Tom's | the chip's dollars per MH/s fall under USD 2.8 by 2028 (approximate) | disagreement with lane 7 row 2.3 recorded; no new parameter, N covers it |
| Used-GPU flood | 15 to 20 M datacentre GPUs installed by end-2026; residual 25 to 35 percent at 60 months; an H100 mines at 0.65x to 3x a 5090, unmeasured | TechInsights, Omdia, mercatus | 1 percent of a retired fleet is 2 to 35x the equilibrium hash | measure an H100 and an A100 this month (measurement); the reward rule (parameter, lane 7 3.1) |
| Rental curve | 0.0117 to 0.0003 to 0.0013 per MH/s-hour by 2036 | model on cloudzero's H100 history | attack dollars unchanged at equilibrium; home share falls 10 to 35x | re-price 51-percent.md from a measured rental yearly (text); the cost-vs-rent line on the earnings page (software) |
| Energy | UK 26.3 p, EU 29 c average, US 17.7 c; heat credit is a third off in the heating season; ERCOT pays industrial curtailment, not homes | Ofgem, Eurostat, EIA, ABC13 | retail-power tiers (UK, DE) are 5 to 9x the industrial price even with heat credited | heat mode, curtailment input, per-region price prompt (software); 2025/422 indicators published (text) |
| Mining rules | Norway (new sites), Sweden (tax), Russia (regions and Moscow), China (illegal), Kazakhstan and Paraguay (licensed, tariffed); US SEC: mining is not a securities offer | the table in 4.4 | a home miner's risk is regional | the region prompt and banned list in Ember (software) |
| Proving cost | USD 1.69 to about 0.005 a block in 20 months; four teams at sub-10 s; EF's 2026 metric is kWh a proof; no prover ASIC has shipped a block benchmark | ethproofs, EF, Cysic | a 12 GB card proves alone under 10 s at every rate; beside its miner only at 3x a year | the shard deadline as a function of the measured fleet median (parameter); two zkVMs and the 1/3 stop switch (switch) |
| Proof-system risk | three soundness-class events in 18 months across SP1 and RISC Zero | LambdaClass, HackenProof, EF | none for miners today; a chain failure only if a proof ever replaces execution for full nodes | never let it (text in spec 10.1); the active-list and stop switch (switch) |
| Light clients | 25 KB per two days (Ethereum), 22 KB (Mina), a 1 MB STARK in under 100 ms on a phone (StarkWare); a verifying Igneum wallet costs under 0.2 percent of a day's battery | a16z, Mina, cryptotimes, model | nothing a miner notices; every miner serves proofs | serve the segment proof from every node by default (software); the Plonk wrapper for phones, the STARK for nodes (parameter) |
| Post-quantum | ML-DSA-44 2,420 B signatures; 57 GB a day of naive votes at 8,192 voters, 223 MB with 250x aggregation; CRQC 28 to 49 percent within ten years; NIST deprecates 2030 | FIPS 204, Cloudflare, GRI, NIST IR 8547, model | a miner signs one succession item at migration; nothing hardware-specific | the sig_scheme byte, the key succession, the PQ precompile, the VDF fallback at genesis (parameters); the aggregated-vote format by 2030 (switch) |
| Regulation of a no-issuer coin | MiCA 4(3)(b) exempts block-reward assets; UK regulates platforms, dealing, custody, staking from 25 Oct 2027, not mining; SEC mining statement; CLARITY stalled; FATF by 2030 | the texts in 8.1 | a pool must not custody; a miner selling is a seller; the publisher is nobody's issuer | the eight-item list of 8.3 (text); the non-custodial pool reference (software) |
| Scenarios | alive in every 2028 and 2031 cell with one parameter each; dies on an unstepped N ladder, on concentration after the home tier leaves, on a late PQ flip, on a single proof system, or on a cap under about USD 20 M | section 9 | the home tiers are the ones each death removes first | the five "needed to survive" rows of section 9 |
## 11. Three headline findings for the coordinator
1. A stored-dataset chip with the class v4 shadow core pays for itself at about USD 100 M of market cap in Igneum's first two years and about USD 700 M in years 5 to 6 (30 percent share, USD 30 M project, model), and it never needs a node below 28 nm plus N5, so the N ladder at genesis is the only lever and C-HBM4E (2027 to 2028) moves the chip's controller under the memory and cuts its dollar cost further.
2. Ten years of rental deflation (USD 0.0117 to 0.0003 to 0.0013 per MH/s-hour by 2036) leaves every 51-percent dollar figure unchanged at the equilibrium and cuts the home card's share of the subsidy 10 to 35x; the day an idle datacentre card on 5 c power sets the rent, a UK home miner at 26.3 p loses 7x on electricity, and the heat mode buys back a third, not the gap.
3. A post-quantum vote at 8,192 voters costs 57 GB a day in naive ML-DSA-44 (19.4 MB a checkpoint) and about 223 MB a day with 250x SNARK aggregation, against a 28 to 49 percent chance of a cryptographically relevant quantum computer inside ten years (GRI 2025) and NIST deprecation after 2030, so the key-succession item, the scheme byte and the aggregated-vote format belong at genesis and the flip belongs in 2030.
File: `/Users/joshm/Projects/igneum-wt-mission/docs/analysis/mission/future.md`.
## Sources (accessed 7 October 2026 unless dated otherwise)
Lane and repository inputs: `docs/analysis/horizon/frontier.md` (lane 7), `docs/analysis/horizon/algorithm.md` (lane 2), `docs/analysis/chip-model-v3.md`, `docs/analysis/51-percent.md`, `docs/bench-log.md` ("Rental cost of hash, 6 October 2026"), `horizon-2026-10.md`, `finality-in-proof.md`, `tail-emission.md`, `vote-or-burn.md`, `prover-tiers-real-cards.md`.
Memory and GPUs:
- TrendForce, NVIDIA fuels HBM4 race, 9 Jan 2026: https://www.trendforce.com/news/2026/01/09/news-nvidia-demand-fuels-hbm4-race-12-layer-ramps-16-layer-push-by-sk-hynix-samsung-and-micron/
- EE Times, The state of HBM4 at CES 2026: https://www.eetimes.com/the-state-of-hbm4-chronicled-at-ces-2026/
- Astute Group, SK hynix 62 percent of HBM: https://www.astutegroup.com/news/general/sk-hynix-holds-62-of-hbm-micron-overtakes-samsung-2026-battle-pivots-to-hbm4/
- siliconanalysts HBM pricing: https://siliconanalysts.com/tools/hbm-analysis
- TrendForce, Micron HBM4E 2027 to 2028, 23 Dec 2024: https://www.trendforce.com/news/2024/12/23/news-micron-plans-hbm4-mass-production-in-2026-customized-hbm4e-to-launch-in-2027-2028/
- Tom's Hardware, TSMC and GUC HBM4E and C-HBM4E: https://www.tomshardware.com/pc-components/dram/hbm-undergoes-major-architectural-shakeup-as-tsmc-and-guc-detail-hbm4-hbm4e-and-c-hbm4e-3nm-base-dies-to-enable-2-5x-performance-boost-with-speeds-of-up-to-12-8gt-s-by-2027
- TechTimes, Samsung HBM4E samples, 30 May 2026: https://www.techtimes.com/articles/317400/20260530/samsung-ships-industry-first-hbm4e-samples-36-tb-s-bandwidth-beats-sk-hynix-six-months.htm
- Tom's Hardware, SK hynix roadmap to 2031: https://www.tomshardware.com/pc-components/dram/sk-hynix-reveals-dram-development-roadmap-through-2031-ddr6-gddr8-lpddr6-and-3d-dram-incoming
- TechSpot, GDDR7 successor after 2028: https://www.techspot.com/news/110151-sk-hynix-expects-launch-ddr6-gddr7-successor-after.html
- TweakTown, RTX 60 Rubin GR20x: https://www.tweaktown.com/news/109619/next-gen-geforce-rtx-60-gpus-rumored-to-use-rubin-gr20x-family-gearing-up-for-2027-release/index.html
- wccftech, RTX 60 2028 launch rumour: https://wccftech.com/nvidia-rtx-60-2028-launch-rumor/
- wccftech, 4 GB and 6 GB GDDR7: https://wccftech.com/4-gb-and-6-gb-gddr7-memory-chips-will-be-rolled-out-in-the-next-two-years/
- TechPowerUp, UDNA 96 CUs: https://www.techpowerup.com/339101/amds-upcoming-udna-rdna-5-gpu-could-feature-96-cus-and-384-bit-memory-bus
- TweakTown, RDNA 5 mid-2027: https://www.tweaktown.com/news/112289/amds-rdna-5-radeon-gpus-will-launch-in-mid-2027-per-new-leak/index.html
- Tom's Hardware, AMD GDDR7 driver support: https://www.tomshardware.com/pc-components/gpus/amd-begins-to-add-gddr7-support-to-its-linux-gpu-drivers-changes-could-herald-use-of-advanced-memory-standard-with-next-gen-radeon-gpus
- VideoCardz, Medusa Halo LPDDR6: https://videocardz.com/newz/amd-ryzen-max-500-medusa-halo-rumored-to-support-lpddr6-memory
- Apple, M5 Pro and M5 Max, 3 Mar 2026: https://www.apple.com/newsroom/2026/03/apple-debuts-m5-pro-and-m5-max-to-supercharge-the-most-demanding-pro-workflows/
- Apple, Mac Studio M5 Max and M5 Ultra, Aug 2026: https://www.apple.com/newsroom/2026/08/apple-introduces-new-mac-studio-with-m5-max-and-m5-ultra/
- JEDEC LPDDR6 press release: https://www.jedec.org/news/pressreleases/jedec%C2%AE-releases-new-lpddr6-standard-enhance-mobile-and-ai-memory-performance
- JEDEC DDR5 JESD79-5D: https://www.jedec.org/standards-documents/docs/jesd79-5d
- Lee et al., Reducing DRAM latency at low cost (latency stagnation): https://arxiv.org/pdf/1604.08041
- Chang et al., Flexible-latency DRAM: https://arxiv.org/pdf/1805.03154
- Wikipedia, Feynman microarchitecture: https://en.wikipedia.org/wiki/Feynman_(microarchitecture)
Chip costs:
- siliconanalysts wafer and mask pricing (Sep 2026): https://siliconanalysts.com/data/wafer-pricing
- siliconanalysts tapeout cost guide, 1 Mar 2026: https://siliconanalysts.com/analysis/fabless-startup-tapeout-cost-guide
- siliconanalysts TSMC 3 nm cost: https://siliconanalysts.com/guide/tsmc-3nm-cost
- SemiWiki, TSMC A14: https://semiwiki.com/forum/threads/tsmc-a14-at-2026-dec-iedm.25920/
GPU supply and rental:
- HPCwire, TechInsights 3.76 M datacentre GPUs 2023, 10 Jun 2024: https://www.hpcwire.com/2024/06/10/nvidia-shipped-3-76-million-data-center-gpus-in-2023-according-to-study/
- Omdia, AI data centre chip market, Aug 2025: https://omdia.tech.informa.com/pr/2025/aug/ai-data-center-chip-market-to-hit-286bn-growth-likely-peaking-as-custom-asics-gain-ground
- Tom's Hardware, Blackwell cabinet forecasts halved: https://www.tomshardware.com/tech-industry/artificial-intelligence/analysts-halve-nvidia-gb200-blackwell-shipment-forecasts-for-2025-prediction-contrasts-ai-boom
- Jon Peddie Research, Q2 2026 AIB shipments: https://www.jonpeddie.com/news/q226-pc-graphics-aib-shipments-increased-10-from-last-quarter-to-12-million-units/
- mercatus-ai, H100 resale value (23 Jun 2026): https://www.mercatus-ai.com/blog/h100-resale-value
- intuitionlabs, used AI GPU prices 2026: https://intuitionlabs.ai/articles/used-ai-gpu-prices-resale-trends
- cloudzero, H100 price 2026: https://www.cloudzero.com/blog/h100-gpu-cost/
- spheron, GPU cloud pricing 2026: https://www.spheron.network/blog/gpu-cloud-pricing-comparison-2026/
Energy, heat, mining rules:
- Ofgem price cap: https://www.ofgem.gov.uk/your-energy-supply/your-energy-bill/energy-price-cap-unit-rates-and-standing-charges
- Eurostat, household electricity prices H2 2025, 5 May 2026: https://ec.europa.eu/eurostat/web/products-eurostat-news/w/ddn-20260505-1
- EIA, US electricity prices: https://www.eia.gov/todayinenergy/detail.php?id=65284
- EIA AEO2025 via The Energy Coop: https://theenergy.coop/blog/unpacking-2025-aeo/
- Cornwall Insight via Solar Power Portal, 10 Jan 2024: https://www.solarpowerportal.co.uk/energy-policy/cornwall-insight-forecasts-lower-gb-power-prices-on-the-long-road-to-truly-affordable-energy-
- spark.money, mining profitability by country: https://www.spark.money/tools/bitcoin-mining-profitability-by-country
- Hashrate Index, Paraguay 2026 (4 May 2026): https://hashrateindex.com/blog/the-state-of-bitcoin-mining-in-paraguay-2026-2/
- miningboard, bitcoin heaters 2026: https://miningboard.com/guides/bitcoin-heaters
- techbuzz on Wired's Heatbit review, 5 Apr 2026: https://www.techbuzz.ai/articles/heatbit-s-bitcoin-mining-heater-fails-the-math-test
- Qarnot (French Wikipedia): https://fr.wikipedia.org/wiki/Qarnot
- ABC13, ERCOT paid Riot USD 31.7 M: https://abc13.com/post/ercot-texas-power-grid-riot-bitcoin-miners/13753300/
- Riot June 2025 update: https://www.globenewswire.com/news-release/2025/07/03/3109856/0/en/Riot-Announces-June-2025-Production-and-Operations-Updates.html
- CoinDesk, Norway ban, 23 Jun 2025: https://www.coindesk.com/tech/2025/06/23/norway-plans-ban-on-new-crypto-mining-data-centers-to-preserve-power
- CoinDesk, Sweden tax, 14 Apr 2023: https://www.coindesk.com/policy/2023/04/14/sweden-drives-final-nail-into-its-bitcoin-mining-industry-with-tax-hike
- crypto.news, Sweden back-tax: https://crypto.news/sweden-orders-six-crypto-firms-to-pay-56m-in-additional-taxes/
- TASS, Moscow mining ban: https://tass.com/politics/2152151
- Cryptopolitan, Russia regions: https://www.cryptopolitan.com/russia-regional-crypto-mining-ban-2025/
- Caspian News, Kazakhstan lifts restrictions, 17 Nov 2025: https://caspiannews.com/news-detail/kazakhstan-lifts-restrictions-on-cryptocurrency-mining-trading-2025-11-17-36/
- KuCoin, Kazakhstan strategic mining from 1 Aug 2026: https://www.kucoin.com/news/flash/kazakhstan-to-enforce-strategic-crypto-mining-rules-from-august-1
- Lightspark, China 2026: https://www.lightspark.com/knowledge/is-crypto-legal-in-china
- egw.news, China provinces (uncorroborated): https://egw.news/crypto/news/30440/china-officially-brings-back-mining-sichuan-inner--NnyU95QrT
- ainfp, Iran mining 2026: https://ainfp.org/mining-crypto-in-iran-legal-status-restrictions-risks
- Dechert, SEC PoW mining statement, Mar 2025: https://www.dechert.com/knowledge/onpoint/2025/3/sec-staff-issues-statement-on-proof-of-work-crypto-mining-activi.html
- Fortune, EIA survey backlash, 1 Mar 2024: https://fortune.com/crypto/2024/03/01/department-energy-survey-bitcoin-miners-legal-backlash/
- Cointelegraph, DAME tax revived: https://cointelegraph.com/news/crypto-mining-tax-united-states-budget
- sazmining, US state mining laws 2026: https://www.sazmining.com/blog/us-crypto-mining-rules-review
Proving:
- EF, Realtime proving, 10 Jul 2025: https://blog.ethereum.org/2025/07/10/realtime-proving
- Ethproofs 2025 review, 6 Dec 2025: https://hackmd.io/@willcorcoran/S1A840ZMZg
- Succinct, SP1 Hypercube on mainnet: https://blog.succinct.xyz/sp1-hypercube-is-now-live-on-mainnet/
- bex.co, Cysic Venus, 17 Apr 2026: https://bex.co/blog/2026/04/17/cysic-venus-multi-gpu-zk-proving-real-time-verification-bottleneck
- bex.co, Airbender, 30 Jan 2026: https://bex.co/blog/2026/01/30/zksync-airbender-fastest-risc-v-zkvm-ethereum-proving
- GitHub comparative analysis, Sep 2026: https://github.com/Ricosworks1/blockchain-payment-flow-analysis/releases/tag/comparative-analysis-ethereum-zk-proving-race-sept-2026
- cryptobriefing, Lattice Jolt, 9 Sep 2026: https://cryptobriefing.com/lattice-jolt-post-quantum-zkvm/
- RISC Zero, R0VM 2.0: https://risczero.com/blog/introducing-R0VM-2.0
- h33.ai, ZK proof companies 2026: https://h33.ai/blog/zk-companies/
- Cysic ZK ASIC docs: https://docs.cysic.xyz/hardware-products/zk-asic-products/
- Ingonyama and Accseal: https://www.ingonyama.com/oldblogs/partnership-announcement-accseal-x-ingonyama
- LambdaClass, SP1 exploit disclosure, 26 Jan 2025: https://blog.lambdaclass.com/responsible-disclosure-of-an-exploit-in-succincts-sp1-zkvm-found-in-partnership-with-3mi-labs-and-aligned-which-arises-from-the-interaction-of-two-distinct-security-vulnerabilities/
- Blockworks, SP1 bug: https://blockworks.co/news/succinct-sp1-bug
- HackenProof, RISC Zero missing constraint, May 2025: https://hackenproof.com/blog/for-hackers/risc-zero-zkvm-missing-constraint-vulnerability
- EF, On formal verification and a bug in SP1 Hypercube, 20 May 2026: https://zkevm.ethereum.foundation/blog/sp1-fv
Light clients:
- a16z Helios: https://github.com/a16z/helios and https://a16zcrypto.com/posts/article/building-helios-ethereum-light-client/
- Ethereum annotated spec, sync protocol: https://github.com/ethereum/annotated-spec/blob/master/altair/sync-protocol.md
- Portal Network: https://ethportal.net/overview
- Mina 22 KB: https://www.gate.com/learn/articles/what-is-mina-protocol/4814
- Celestia Lumina: https://github.com/celestiaorg/lumina
- Lightning Labs Neutrino: https://github.com/lightninglabs/neutrino
- Blixt features: https://blixtwallet.github.io/features
- StarkWare 1 MB Bitcoin verifier, 11 Sep 2025: https://www.cryptotimes.io/2025/09/11/starkware-unveils-1mb-bitcoin-verifier-for-mobile-devices/
- Mopro benchmarks: https://zkmopro.org/docs/0.2/performance/ and https://hackmd.io/@vivi432/mopro-benchmark
- provebench: https://github.com/agnij-dutta/provebench
- shattered.io, STARK 45 KB verify: https://shattered.io/bulletproofs-vs-zk-starks-2026/
- Wikipedia WebGPU: https://en.wikipedia.org/wiki/WebGPU
- Zcash Tachyon-Lite grant: https://forum.zcashcommunity.com/t/grant-proposal-tachyon-lite-light-client-sdk-and-sync-proof-server-for-zcash/55671
Post-quantum:
- Cloudflare, ML-DSA will have to do, 9 Jul 2026: https://blog.cloudflare.com/ml-dsa-will-have-to-do/
- encryptionconsulting, FN-DSA FIPS 206: https://www.encryptionconsulting.com/education-center/fn-dsa-fips-206/
- encryptionconsulting, NIST IR 8547 deadlines: https://www.encryptionconsulting.com/nist-ir-8547-2030-2035-action-plan/
- NIST PQC standardisation: https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization
- Global Risk Institute, Quantum Threat Timeline Report 2025: https://globalriskinstitute.org/publication/quantum-threat-timeline-report-2025b/
- postquantum.com, Google ECDLP resources: https://postquantum.com/security-pqc/google-quantum-bitcoin-ecdlp/
- postquantum.com, 835 logical qubits (arXiv 2607.13816): https://postquantum.com/security-pqc/ecc-secp256k1-835-logical-qubits/
- arXiv, Brace for impact (ECDLP challenges): https://arxiv.org/pdf/2508.14011
- ethereum.org, post-quantum cryptography: https://ethereum.org/roadmap/security/quantum-resistance/
- The Quantum Insider, EF PQ team, 26 Jan 2026: https://thequantuminsider.com/2026/01/26/ethereum-foundation-elevates-post-quantum-security-to-top-strategic-priority/
- The Quantum Insider, BIP-360 testnet, 20 Mar 2026: https://thequantuminsider.com/2026/03/20/btq-technologies-implements-bip-360-quantum-resistant-bitcoin-transactions-testnet/
- qsha256, BIP-360 and BIP-361: https://qsha256.com/blog/bitcoin-pq-migration
Regulation:
- Osborne Clarke, MiCAR white papers and Bitcoin, 4 Oct 2023: https://www.osborneclarke.com/insights/what-are-eus-white-paper-requirements-micar-and-do-they-apply-bitcoin
- Conventus Law, crypto-assets without an identifiable issuer: https://conventuslaw.com/report/crypto-assets-without-an-identifiable-issuer-regulatory-reality-two-years-post-micar-application-date/
- Latham, MiCA white paper and sustainability disclosures: https://www.lw.com/en/markets-in-crypto-assets-regulation-tracker/mica-white-paper-sustainability-disclosures
- carbon-ratings, MiCA sustainability indicator methods: https://carbon-ratings.com/dl/whitepaper-mica-methods-2024
- European Commission, 2026 MiCA review targeted consultation (reply by 31 Aug 2026): https://finance.ec.europa.eu/document/download/62be7015-f066-4fac-b74e-71bacdbcc9f5_en?filename=2026-mica-review-targeted-consultation-document_en.pdf
- ESMA, end of MiCA transitional periods, Apr 2026: https://www.esma.europa.eu/sites/default/files/2026-04/ESMA75-113276571-1679_Statement_on_the_end_of_transitional_periods_under_MiCA.pdf
- FCA, cryptoasset regime policy statements: https://www.fca.org.uk/publications/policy-statements/cryptoasset-regime
- Lewis Silkin, UK draft Regulations and perimeter guidance, 30 Sep 2026: https://www.lewissilkin.com/insights/2026/09/30/uk-cryptoasset-regime-draft-regulations-and-fca-perimeter-guidance-provide-furth-102o3vf
- Skadden, FCA finalises core rules, Jul 2026: https://www.skadden.com/insights/publications/2026/07/fca-finalises-core-rules-for-the-uk-cryptoasset-regime
- Orrick, CLARITY stalls, 2 Oct 2026: https://www.orrick.com/en/Insights/2026/10/The-CLARITY-Act-Stalls-in-the-Senate-Whats-Next-for-Digital-Asset-Regulation
- FATF, travel rule supervision best practices, Jun 2025: https://www.fatf-gafi.org/content/dam/fatf-gafi/recommendations/Best-Practices-Travel-Rule-Supervision.pdf
- Sumsub, FATF Recommendation 16 revision: https://sumsub.com/media/spotlight/same-rule-same-problems-will-fatf-travel-rule-fix-the-divide/
- Dechert, DFSA crypto token regime, 13 Jan 2026: https://www.dechert.com/knowledge/onpoint/2026/1/dubai-updates-crypto-token-regulatory-framework.html
- TradingView/Coinpedia, UAE and VARA 2026: https://www.tradingview.com/news/coinpedia:681009ff8094b:0-crypto-regulations-in-uae-dubai-in-2026/

View file

@ -0,0 +1,528 @@
# The last mission, lane 4: what can be invented, judged hard
7 October 2026, morning UK. Lane 4 of the final research programme ("the last mission"), worktree `igneum-wt-mission`. The question: given everything Igneum already has (the horizon one page, the frontier lane's sixteen ideas, the new-PoW lane's three schemes, class v5, finality in the proof, work-stake, the tail, vote-or-burn, the ladder, the pool design, the light client, the phone app), what is the NEXT genuinely new thing a GPU chain could do that none has. Every candidate here was checked against prior art by name and year, run through its own game theory with a model this lane ran (`invent_model.py`, section 0), reviewed in the Monero or Kaspa developer's voice, priced in agent hours with a first gate, and given its per-tier consequence and four persona verdicts. Nothing here touches the devnet. No em dashes. Figures from memory say approximate; figures from a source name it.
the project lead's rulings are applied as a filter before any idea is scored: miners are the security always; no stake and no coin bond; no holder penalised; no device bounty; no fixed-height activations; no calendar dates; no reliance on another chain; no dev fund; no privacy; nothing that becomes a token sale; the lottery and the proving stay separate; emission carries security with no end date. An idea that needs one of these is marked dead in one line.
## 0. Progress, method and the four voices
| Time (UK) | State |
|---|---|
| 08:05 | Lane started; read CLAUDE.md, the horizon one page (sections 1 to 3), frontier.md (sections 0 and 3, all sixteen), new-pow.md (3, 4, 6, 7), class-v5-stored-state.md, finality-in-proof.md, work-stake.md, tail-emission.md (one page), vote-or-burn.md, latency-ladder.md, 51-percent.md, pool.md, spec 09, spec 10, phone-app.md, the four persona files, bench-log (rental cost, warp verify, aggregation, 5090 rows) |
| 08:35 | Prior art checked by WebFetch on primary pages (the session's WebSearch budget was already spent; every page that answered is in the sources list; four pages 404'd and those items are labelled approximate) |
| 08:51 | `invent_model.py` written and run in the lane's scratch (`mission-invent/out.md`); every table below marked "model" is printed by it |
| 08:59 | This file written (528 lines, 0 em dashes, not staged); final message to the coordinator |
**Method.** Three passes per candidate. (1) Prior art: the paper, project or repository that did it, with the year, and the one sentence of what differs. (2) Game theory: who gains from cheating, the attack, its cost, the bound; a short numeric model actually run. (3) The hostile review in the Monero or Kaspa developer's voice, then the prototype cost in agent hours, the first measurable gate, the per-tier consequence (home miner 8 / 12 / 16 / 24 to 32 GB, rig, pool user; Windows, Linux, macOS; NVIDIA, AMD, Apple) and four persona verdicts: do now, prototype, watch, never.
**The four voices.** The cryptographer, the consensus engineer and the miner (the miner-community lead) are the persona files in `.claude/agents/`. The fourth, the economist, is defined here from the economy lane's method (`docs/analysis/horizon/economy-and-utility.md`, `tail-emission.md`): every number is priced in rented hash at the measured USD 0.0117 per MH/s-hour (bench-log, "Rental cost of hash", 6 October 2026); an IGN price is an input never a prediction, shown at USD 0.005, 0.02 and 0.10; fees are never assumed to be the security budget; a mechanism that moves income is judged by who pays, who is paid, and whether the payer would rather leave; the per-tier consequence is stated before anyone asks.
**Price basis used throughout.** Subsidy 100 IGN a block at one block a second (the tail-emission recommendation; today's code pays 31.688). Rented hash USD 11.7 per GH/s-hour. CPU verify of one 32-lane unit: 0.441 ms class v3 steady (bench-log line 170), 5.06 ms class v4 cold on the box's core (horizon L2), 1.35 ms per pool share check in isolation (pool.md section 5); the gate is 10 ms. Header 400 B working figure (spec 10.9). Snapshot 114.8 MB (horizon rank 22). Groth16 proof 260 B (SP1 docs), public values with the finality extension 494 B (finality-in-proof section 1).
**What the measurement budget did not allow.** Nothing in this lane needed the box or a GPU pod to reach a verdict; where a first gate needs one, the gate names the command and the expected number and the final message lists it for the coordinator.
---
## 1. Hashing useful to the chain itself, without reopening the useful-work trap
The trap, restated from new-pow section 3.1 and frontier 3.10: a lottery needs a sampleable puzzle with a cheap verifier; any coupling of the puzzle to a scarce skill hands the lottery to the best at that skill (Aleo). The four variants below avoid the trap by keeping the hash kernel byte for byte as shipped and changing only what a miner must HOLD or must have DONE to build the dataset or to be paid. That is class v5's shape (new-pow scheme C: hash rate 63.083 against 63.088 MH/s on the 4090, build +1.4 ms, verifier +0.11 to 0.21 ms per unit), so the question for each is only: what does it add to class v5 that is measurable, and does the addition survive its own game.
### 1.1 What class v5 already delivers, so nothing below re-invents it
| Property | Delivered by class v5 | Where |
|---|---|---|
| Every mining operation holds the day's execution state | yes, by construction: `leaf(t) = D[t mod n]` keys every item; a stateless hasher is wrong on every item (the known-failed case) | class-v5 section 3, 4 |
| Every block names 128 random state leaves per lane any full node can open against `R_d` | yes; the opening RPC is new-pow rank 6 (4 hours, not built) | new-pow 3.3, 7 |
| The miner must know the chain to within the epoch lead | yes, already since class v3: the program is the 10-minute VDF of a certified checkpoint 20 minutes before the epoch (spec 04 4.3); a miner without the last hour of chain has the wrong program and every hash is wrong | spec 04 |
| The f = 0 recompute chip must hold the state | yes | new-pow 6 |
| The pool caveat | stated: a pool ships `D` once a day (6 KB today, 1 to 2 GiB on a used chain) | class-v5 section 3 |
### 1.2 (a) Proof of following: the day's leaves include the last N blocks
**The idea.** Widen class v5 so that the dataset derives from the state AND from the chain's recent blocks: the day's leaf array gains the hashes or receipts of the last N chain blocks before the cut, so a miner proves it relayed or held recent blocks, not only the state.
**Prior art.** Verthash (Vertcoin, January 2021, approximate: the vertcoin.org page 404'd this morning): a 1.2 GB dataset built from the chain's own block headers, random reads per hash. Ethash (2015): dataset from the epoch seed. Class v5 (this project, 7 October 2026): dataset from the execution state. Permacoin (Miller, Juels, Shi, Parno, Katz, IEEE S&P 2014): proof of retrievability of a dealer's file. The combination "state plus recent headers" is new in form; Verthash is the nearest in substance.
**Mechanism.**
| Item | Rule |
|---|---|
| Extra leaves | after the state records, one record per chain block in `(daa(C_d) - N, daa(C_d)]`: `0x04 ‖ block_hash ‖ state_root ‖ receipts_root` |
| Keyed by | `R_d` as every other leaf; the day's cut `C_d` is one hour before the day (class-v5 section 2) |
| What it forces | a builder must hold the last N headers and receipt roots before the cut |
| What class v5 forces already | the whole state after `C_d`, which commits to every one of those blocks through `R_d` |
**Game theory.** Nobody gains from cheating because there is nothing to cheat: the state root already commits to the chain. The only question is what a miner must HOLD. Under class v5 a miner holds `D` (the state sample); under 1.2 it also holds N header records it can fetch from any peer in one round trip. Model (section A of `invent_model.py`, the outsourcing row): a key with nothing answers a fetch in about 108 ms over a 100 ms link. The addition forces no holding that a pool's daily delivery does not already satisfy, and the "following" it proves is the following the epoch seed proves every hour at zero cost.
**What is measurable.** Nothing new per block. The receipts are a function of the state transition every executing node already computed; the day's cut already requires the chain to within an hour; the epoch seed requires it to within 80 minutes. The one measurable thing would be a per-block dataset change, and a per-block build is 32 ms on a 4090 (class-v5 section 2) against a 1,000 ms block: a 3.2 percent hash loss on every card every second for a property the program swap gives every hour for free.
**Hostile review (Kaspa voice).** "You have a dataset keyed by a state root that is itself a function of every block in the chain's past. Adding the last N block hashes as leaves adds information the root already carries. If you want 'following', the program swap is your following: a miner that is an hour behind has the wrong kernel. Do not add bytes to a build that already proves the thing."
**Cost and gate.** 0 hours: not built. If someone insists: the gate is the fast-time harness showing a stateful miner with stale headers is refused, which the state root already does.
**Per tier.** No change for any card, rig or pool user; the verifier's RAM unchanged.
**Verdicts.** Cryptographer: never (the root commits to the chain; redundant). Consensus engineer: never (bytes for nothing). The miner: never (nothing to see). Economist: never (no income moves). Verdict: never, with the sentence "proof of following is the epoch seed plus class v5" written into class-v5's litepaper paragraph.
### 1.3 (b) Proof of serving: a reward component for serving headers, snapshots and proofs
**The idea.** A slice of the producer's 80 points is paid only to keys that served data to peers in the window, verified by challenge-response sampled into blocks.
**Prior art.** Filecoin WindowPoSt (2020; spec.filecoin.io: 48 deadlines of 30 minutes a day, randomness from a beacon 20 epochs before the deadline, fee debt on a missed proof); Arweave SPoRA (version 2.4, February 2021, approximate: the docs page 404'd; mining reward requires random access to stored chunks); Sia storage proofs (2015, approximate) and Storj audits (2018, approximate); Celestia data availability sampling (2023, approximate); EigenDA (2024, approximate); Ethereum PeerDAS (EIP-7594, 2024: custody by node id, cell KZG proofs, and the EIP states no reward or penalty for serving); Kaspa archival nodes (a flag on kaspad, unrewarded; the README fetched this morning does not document it, approximate). What differs here: the data served is the chain's own state, the challenger is the next block producer and the randomness is the chain's, and the reward is a slice of the block subsidy to a miner key, not a storage market.
**Mechanism.**
| Item | Rule |
|---|---|
| Challenge | block B's producer draws `c` keys from the weight table at the last certified checkpoint in B's past, by weight, seeded by B's prehash; for each, 8 leaf indices of the day's `D` |
| Answer | the challenged key signs `(B, leaves, openings against R_d)` and any producer carries it within `T` blocks |
| Failure | no answer carried in `T` blocks after B |
| Reward | x of the 80 producer points conditional: a key with an unanswered challenge in the window is paid 80 - x on its next blocks until it answers one |
| Bytes | 8 leaves x (64 + 25 x 32) + 96 B signature = 6.8 KB per answer; 1 challenge per block = 0.61 GB a day on every node (model, table A2) |
**Game theory (model, section A).**
| Attack | Cost | Bound |
|---|---|---|
| Serve yourself from your own nodes | zero; the challenged key answers its own challenge from the state it already holds to mine under class v5 | the proof reduces to "I hold what class v5 already makes me hold" |
| Outsource the answer to a peer that holds the state | one fetch, about 108 ms on a 100 ms link; any deadline over one block (1,000 ms) admits it | the proof becomes "someone with the state answered"; Filecoin's answer is sealing (replicas slower to fetch than to read), which costs hours of CPU per sector and does not fit a daily dataset |
| Producer griefing: refuse to carry answers | an answer gossips to every producer; withholding for T blocks needs a majority of producers for T seconds | the same bound finality lives with |
| Sybil the draw | the draw is by weight; a dust key is never drawn; splitting a key splits its draws and its loss | nothing to gain |
| Loss to a key that never serves at x = 8 | 0.1 percent key: 691 IGN a day (USD 3.5 at 0.005); 10 percent key: 69,120 IGN a day | the price of not running a node, which a miner under class v5 must run anyway |
**Load per key.** At 10,000 keys and one challenge per block a key's share of challenges is its weight share: 8.64 a day for a mean key, 0.06 MB of upload a day, 0.006 kbit/s. At 128 leaves per challenge and 8 per block, 7.6 MB a day. Every home connection carries it (table A1). The cost is on the chain, not the key: 0.61 to 76.5 GB a day of answers on every node depending on the two parameters.
**Hostile review (Monero voice).** "You pay a miner for proving it holds the thing your own lottery forces it to hold. The challenge adds 0.6 GB a day to every node to learn nothing, and the fetch bound makes it 'someone served', which is what gossip already guarantees. Filecoin pays for storage because storage is the product; your product is blocks. The one honest version is unpaid: a light-client spot check of availability, which is your rank 6 RPC."
**Cost and gate.** 0 hours as a reward; 4 hours as new-pow rank 6 (the opening RPC, unpaid), whose gate is 128 openings verifying against `R_d` on the fast-time network.
**Per tier.** As a reward: every tier pays bytes (0.61 GB a day of chain) to prove what class v5 proves. As the unpaid RPC: a node serves 102 KB per request on demand; a light client gains a daily availability spot check; no card changes.
**Verdicts.** Cryptographer: never as a reward, do the RPC (the outsourcing bound makes the proof vacuous). Consensus engineer: never (0.61 to 76 GB a day for no new property). The miner: never (a line item nobody understands). Economist: never (it moves x points for a service already compelled). Verdict: never as protocol; new-pow rank 6 stands.
### 1.4 (c) Proof of propagation: signed receipts from peers in the next block
**The idea.** A block carries receipts, signed by peers' vote keys, that they received the previous block within t seconds; the producer is paid a slice for fast propagation.
**Prior art.** Bitcoin's Relay Network and FIBRE (Matt Corallo, 2016; bitcoinfibre.org: UDP, forward error correction, compact blocks; no protocol payment to relays). Kaspa's relay is the ordinary p2p flow with no receipts (approximate). "Proof of relay" papers: this lane found none that shipped; the arXiv search for "proof of latency" returned five unrelated papers (section 7.11). GHOSTDAG itself: a slow block is red and its subsidy goes to its merger (spec 02 2.5), which is the propagation reward the DAG already pays.
**Mechanism and why it dies.**
| Item | Problem |
|---|---|
| The time field | no consensus clock finer than Kaspa's timestamp window (a header at most 10 s ahead of the clock, spec 02; the DAG tolerance 132 s in frontier 3.1); a receipt's "within t seconds" is the signer's word |
| Sybil receipts | peers are keys; weight-drawn receipts cost the attacker nothing because its own keys sign its own receipts |
| Bytes | 8 receipts x 136 B = 1,088 B per block, 94 MB a day; 32 receipts 376 MB a day (model, section H) |
| What the DAG already does | at 1 block/s on Devnet 2 run B the red rate was under 2 percent from minute six (bench-log, "Block rate on Devnet 2"); a block that propagates slowly is red and its subsidy moves to its merger: the propagation reward exists and is measured in blue blocks, which are also the vote weight |
**Hostile review (Kaspa voice).** "GHOSTDAG is a proof of propagation. Blue means it arrived in time; red means it did not; the k parameter is the clock. Receipts signed by the people who benefit from them prove nothing and cost 94 MB a day."
**Verdicts.** All four: never. Cost 0.
### 1.5 (d) Proof of state availability with block-derived challenges and the producer's own next block
**The idea.** As 1.3 but the challenge is issued by the producer's own next block (so no trusted party), answered on demand, and the reward slice is paid only to keys that answered.
This is 1.3 with the challenger named. The trap the brief names ("who issues challenges without a trusted party") is answered correctly by block-derived randomness and the producer's next block, and the answer does not rescue the idea: the outsourcing bound (a fetch in 108 ms) and the self-serving bound (the key answers from the state class v5 makes it hold) are unchanged. The one new element, "the producer's own next block" as the carrier, makes the producer the judge of its own challenge and needs a second producer to carry the answer for fairness, which is 1.3's `T` blocks.
**Verdicts.** All four: never as a reward; the unpaid availability spot check (new-pow rank 6) is the whole of what survives. Cost 4 hours for the RPC.
### 1.6 Section 1 in one table
| Variant | Prior art | New? | Survives its game? | Cost | Verdict |
|---|---|---|---|---|---|
| (a) proof of following | Verthash 2021; class v5 2026 | in form only | yes, because it does nothing | 0 | never: the epoch seed and the state root already prove following |
| (b) proof of serving | Filecoin PoSt 2020; Arweave SPoRA 2021; PeerDAS 2024 (unrewarded) | the reward to a miner key is new | no: outsourced in 108 ms; self-answered under class v5 | 0 (4 for the unpaid RPC) | never as a reward |
| (c) proof of propagation | FIBRE 2016 (unpaid); GHOSTDAG's reds | no | no: time is unverifiable; receipts are Sybil-free | 0 | never |
| (d) state availability by the producer's next block | same as (b) | the challenger rule is new | no, same bounds as (b) | 4 (RPC) | never as a reward |
---
## 2. A block reward that pays for availability of the chain's state
**The exact split proposal, as asked.** Of the 80 producer points, x are conditional on the key having served state in the window, verified as in 1.5; the rest unconditional. The candidate x: 2, 4 or 8 (8 would mirror the signing bonus of vote-or-burn, which pays 8 of the 80 for signing).
**The attack: serve yourself.** The challenged key answers from the state it holds; the challenge is drawn by weight, so the key's own weight is the only thing that decides how often it is asked. A key that runs a node (every class v5 miner) passes every challenge at zero marginal cost. A key that runs no node and proxies to a pool passes every challenge at one fetch. Nobody fails except a key whose node is down, which is the signing bonus's case already (vote-or-burn section 1: the honest-silence classes), so the conditional slice is a second liveness bonus on the same event.
**The Sybil bound.** Vote-key weight as the challenge draw: a dust key is never drawn, a split key is drawn in proportion, so splitting gains nothing. Correct, and it also means the mechanism measures the keys that already mine, who already hold the state.
**Per-tier cost (model, table A1).** At 10,000 keys, one challenge per block, 8 leaves: a mean key uploads 0.06 MB a day; at 8 per block and 128 leaves, 7.6 MB a day, 0.7 kbit/s. Any home connection on any OS carries it. The chain pays 0.61 to 76.5 GB a day of answer bytes on every node for the two parameter corners.
**What it costs a key that never serves (model, table A3).** At x = 8: 0.01 percent key 69 IGN a day, 0.1 percent 691, 1 percent 6,912, 10 percent 69,120 (USD 0.3 to 346 at 0.005). The same shape as the signing bonus and for the same population.
**Hostile review (Monero voice).** "Two liveness bonuses on one event is one bonus with worse accounting. Your signing bonus already pays 8 points for 'my node is up and following'; this pays x more for 'my node is up and holds the state', which under class v5 is the same node. Merge them or drop this."
**The economist.** No payer wants it: the slice comes from the same producer share, so it is a transfer from keys whose nodes are down to keys whose nodes are up, which the signing bonus already does; the chain pays gigabytes a day for the second accounting.
**Verdicts.** Cryptographer: never (vacuous under the outsourcing bound). Consensus engineer: never (bytes). The miner: never (a second deduction line is read as a second fine; vote-or-burn's 93 to 97 percent respect for one bonus at genesis would not survive two). Economist: never. Cost 0.
---
## 3. Mining that is also a light-client service
**The idea.** Every miner's node serves finality-in-proof public values (494 B) and certificate bitmaps to phones; a reward slice or a fee market pays for it.
**Prior art.** Ethereum Portal Network (2021 to 2026; ethportal.net: history, state and beacon networks; clients Trin, Nimbus Portal (Fluffy), Ultralight, Shisui; the site states no reward for nodes). Helios (a16z, 2022, approximate for the year; github: weak-subjectivity checkpoints as the root of trust, sync-committee verification). Mina's snarkers (2021, approximate): a fee market for SNARK work inside the protocol. Celestia light nodes and bridges (2023, approximate). What Igneum has that none of these had: the serving node is a miner with a funded key, and the object served (494 B of public values plus a 260 B Groth16 proof, once the wrapper lands) is tiny and self-certifying.
**Whether it is a protocol item.** No. The object is public values a node already holds; serving it is one HTTP or wss endpoint (spec 10.7's read-only table); the phone app already reads nodes it pins (phone-app section 5). A fee market for 786 bytes is a transaction per fetch at 0.0051 IGN (frontier 3.13's transfer floor), which no phone will pay per refresh and no node needs. A reward slice is 1.3's reward with a different payload and the same vacuity.
**What it is: an Ember feature.** Ember in verify mode is frontier 3.8 (do now, 20 hours). The light-client serving side is a line in the node's RPC: `igneum_getLatestWrappedProof`, served to any client, rate-limited per IP, with the phone app pinning the user's own node by its card (phone-app section 5) or the seed list. Bytes per day per phone: 786 B per refresh, 2,880 refreshes a day if it polls every checkpoint = 2.3 MB (spec 10.5's phase-two figure, 2.30 MB, matches).
**Game theory.** A node that lies serves a proof that does not verify, which the phone refuses; a node that withholds is replaced by the next pinned node. No payment, so no cheating for pay. The one attack is topology: a phone pinned to one node is eclipsed by that node, which spec 10.6's N of M seed agreement bounds.
**Hostile review (Kaspa voice).** "Serving 786 bytes is not a service you price. It is a feature of a node. Put it in the app."
**Cost and gate.** 4 hours (the RPC and the rate limit) on top of frontier 3.8's 20; gate: a phone on cellular shows "locked, voter set verified in the proof" from a miner's Ember node with no other node asked, bytes counted on the Verify screen.
**Per tier.** Every miner's Ember serves phones by default behind a per-IP limit (a home upload of 786 B per request is nothing); a holder's phone gets its proof from any miner; a pool user's member process is the same Ember; no card or OS difference.
**Verdicts.** Cryptographer: do now (as the Ember line). Consensus engineer: do now, not a protocol item. The miner: do now ("my node serves my phone" is a sentence miners like). Economist: do now, unpaid; a fee market here would price a service below its transaction cost.
---
## 4. A decentralised pool in the protocol
### 4.1 The design, as asked
| Item | Rule |
|---|---|
| A share | a block header at a low difficulty, signed by the miner's own payout key, referencing the round `r` |
| The round | the window of blocks between two chain-block boundaries, e.g. 600 chain blocks (the record window of spec 7.8) |
| Carriage | any block carries shares it has seen; a share is valid if its header's PoW passes the share target and its parents are in the carrier's past |
| Payout | a coinbase rule every node computes: the producer share of blocks in round r is split by share weight (`2^-s`) over the shares carried in round r's blocks, PPLNS style, minus nothing (no operator, no fee) |
| Variance reduction | a miner is paid by its shares whether or not it found a block |
### 4.2 Prior art
| Name | Year | What it did | What differs |
|---|---|---|---|
| P2Pool (Bitcoin) | 2011 (Forrest Voight, approximate) | a sidechain of shares at a 10-s target; payouts in the coinbase of found blocks; no operator | the shares were off the main chain; nodes did not verify them |
| FruitChains | Pass and Shi, 2016 (eprint 2016/916) | "fruits" as low-difficulty PoW objects carried in blocks, rewarded fairly: any honest set with phi of the hash gets at least (1 - delta) phi of the reward | the exact in-protocol shape asked for here, published nine years ago; never shipped on a major chain |
| SmartPool | Luu, Velner, Teutsch, Saxena, 2017 (eprint 2017/019) | shares committed by Merkle root to an Ethereum contract, verified by sampling; miners paid 0.6 percent of block rewards in transaction fees | a contract, not a coinbase rule; the operator is the contract |
| Monero P2Pool | SChernykh, 2021 (github SChernykh/p2pool) | a 10-s share sidechain merge-mined with Monero, PPLNS over 2,160 shares (6 hours), no operator, payouts as coinbase outputs | off the main chain; Monero nodes do not verify shares |
| Stratum V2 job negotiation | Braiins, 2019 onward (approximate) | the miner builds its own template; the pool must pay shares on it | an operator remains; the vote and template are the miner's (spec 09 already takes this) |
| Ocean (Bitcoin) | 2023 (approximate) | an operator pool with on-chain payouts per block (TIDES) | an operator remains |
| Braidpool | 2021 onward (github braidpool/braidpool: in development, not production) | a DAG ("braid") of shares; miners build their own blocks; constant-size payouts | not shipped |
| Kaspa "SPECTRE shares" | none found | | Kaspa pools are Stratum bridges with operators (approximate) |
So the in-protocol pool is FruitChains (2016) with Igneum's payout key and round. It is not new.
### 4.3 The bytes and the verifier (model, section B)
| Miners | Share interval | Shares per block | Bytes per block (compact 169 B) | Per day on every node | Verifier cores at 1.35 / 5.06 / 10 ms per share |
|---|---|---|---|---|---|
| 1,000 | 10 s | 100 | 16.5 KB | 1.5 GB | 0.14 / 0.51 / 1.0 |
| 10,000 | 10 s | 1,000 | 165 KB | 14.6 GB | 1.35 / 5.06 / 10.0 |
| 100,000 | 10 s | 10,000 | 1,650 KB | 146 GB | 13.5 / 50.6 / 100 |
| 100,000 | 100 s | 1,000 | 165 KB | 14.6 GB | 1.35 / 5.06 / 10.0 |
| 100,000 | 1,000 s | 100 | 16.5 KB | 1.5 GB | 0.14 / 0.51 / 1.0 |
The full-header form (496 B) is 2.9x the bytes. The verifier at the class v4 cold figure (5.06 ms) needs 50 cores per node at 100,000 miners and a 10-s share interval, which no home node has; at a 1,000-s interval it fits one core and 1.5 GB a day, but then the variance reduction is the thing being bought and it has gone:
| Income source | Paying events per day | CV of a day's income | CV of a month |
|---|---|---|---|
| solo 17 MH/s at 1 TH/s | 1.5 | 82.5 percent | 15.1 percent |
| shares at 1 per 1,000 s | 86 | 10.8 percent | 2.0 percent |
| shares at 1 per 100 s | 864 | 3.4 percent | 0.6 percent |
| shares at 1 per 10 s | 8,640 | 1.1 percent | 0.2 percent |
At 100,000 miners the chain can afford one share per 1,000 s per miner (1.5 GB a day, one core), which gives a small card a 10.8 percent daily CV: a real improvement on 82.5 percent, at the cost of 1.5 GB a day on every node including every phone-class light client that would want to verify the coinbase. At 10,000 miners and 100 s the same bytes buy 3.4 percent.
### 4.4 Does the vote key and sortition machinery give a round for free?
Yes for the ROUND, no for the SHARES. W2 already counts blue blocks per key over 30 days, and the shard sortition already draws by that count (spec 7.2). A "round" and a per-key tally exist in every node. What does not exist is a sub-block unit of work, and that is the whole cost: every share is a PoW object every node verifies. The free version is to pay by BLOCKS over a window, which the protocol already does (every block pays its producer), so the free "pool" is the chain itself, and its variance is the solo row above.
### 4.5 The attacks
| Attack | Effect | Bound |
|---|---|---|
| Share withholding (find a block, publish only shares) | in an operator pool the withholder is paid shares and the pool loses the block; here the round's payout IS the blocks found, so a withheld block shrinks everyone's payout including the withholder's own share of it: the withholder loses `(1 - its share) x 80` points and gains nothing | self-defeating; FruitChains' fairness bound is the formal version |
| Share stuffing | every share is PoW at the share target, so a fake share costs its hash; stuffing is mining | none needed |
| Share grinding on the round boundary | a share's round is fixed by its parents; a share straddling a boundary is a DAG event nodes already order | none needed |
| A majority refusing to carry others' shares | it earns the majority a larger split of the round; this is red-flooding by another name, 26 to 28 percent of honest income at 51 percent (51-percent.md section 1) | the same bound as today's reds |
| Verifier DoS | a flood of invalid shares costs a node 5 ms each before rejection | the per-peer rate limits of the p2p layer; the ban score |
### 4.6 The honest verdict against docs/plans/pool.md
The shipped pool v0 (5 October 2026, rebased 6 October) already removes the two things an in-protocol pool is for: the operator holds no key and no vote (members sign their own votes through their own verifiers, spec 9.7), and the share rule is fixed by spec 9.8 so the member keeps its own ledger. The measured operator cost is 1.35 ms per share check (4,800 to 22,700 members per core) and 1 percent fee by default. What the operator still controls: transaction choice for mode A members who do not check (mode C fixes it), and the payout ledger's honesty (the member's own ledger plus the chain's blocks under its key bound it).
The finished form is therefore the pool design plus one addition the brief names: **a verifiable payout contract**, which is SmartPool (2017) on Igneum's EVM: the operator posts the round's share Merkle root and the payout list; any member can prove under-payment with its own share log against the root; the contract pays from the pool address. Cost 16 hours (contract 6, operator posting 4, member proof and the Ember line 6). Gate: a member whose share is dropped from the root proves it on the fast-time network and is paid; an honest round costs the operator one transaction. Bytes on chain: 32 B per round per pool. Verifier cost on nodes: nothing per share.
**Hostile review (Monero voice).** "P2Pool exists because we did not want shares on the main chain; your numbers say why: 14.6 to 146 GB a day. Our P2Pool is a sidechain nobody but miners runs. Build that if you want no operator; it costs your chain nothing." Answer: a Monero-style P2Pool sidechain for Igneum is an app a pool operator could ship (the share chain's only chain-side object is the coinbase payout list), and it is the same code as the pool v0 member minus the server; the lane recommends the contract first because it keeps every existing pool (HiveOS, WhatToMine listings) and makes them verifiable.
**Per tier.** Home miner on any card: nothing changes in the worker; under the contract a member can prove under-payment from its own log. Rig: one key per rig as today. Pool user: the pool's round is public. Node operator: 32 B per round per pool instead of 1.5 to 146 GB a day. Light clients: unchanged.
**Verdicts.** Cryptographer: never in protocol (FruitChains is the prior art and the bytes are the reason it never shipped); prototype the contract. Consensus engineer: never in protocol (50 cores per node at 100,000 miners on a 10-s share); the contract 16 hours. The miner: never in protocol (a chain that grows 14.6 GB a day from shares is the first thing a reviewer attacks); the contract is what listings want. Economist: the operator's 1 percent is already below SmartPool's 0.6 percent plus gas (approximate); the contract makes the 1 percent honest. Verdict: never in protocol; prototype the verifiable payout contract, 16 hours.
---
## 5. Heat as product
**The idea.** Ember's "heat mode" targets a room temperature or a schedule: the card mines when the room wants heat and idles when it does not; the chain does nothing.
**Prior art.** Heatbit (2022 launch, approximate; heatbit.com this morning lists Bitair at 25 W, 1.2 TH/s, USD 179 to 249, and names earlier Maxi and Trio models), 21energy (Austria; Ofen 3 heaters EUR 1,658 to 3,325, "7 to 10 kW" central-heating models coming, 21energy.com), Qarnot (France, founded 2010, approximate, the Wikipedia page 404'd; QRad computing heater 2013, approximate; sells HPC and heats buildings), MintGreen in North Vancouver (2021, approximate), the Finnish and French district-heat trials (approximate; no page fetched). Every one is an ASIC or HPC box sold as a heater. None is a GPU chain's own client with a thermostat. Ember's version is new as a client feature and nothing else.
**Numbers (model, section C).** A 300 W card delivers 300 W of heat at the card's electricity price. The competition is a gas boiler at 90 percent or a heat pump at COP 3.
| Region | Card per hour | Gas boiler, same 300 W | Heat pump COP 3 | Resistive electric | Card must earn per hour to match boiler / heat pump |
|---|---|---|---|---|---|
| UK (Ofgem, 1 Oct to 31 Dec 2026: 26.32 p electricity, 7.97 p gas) | 7.90 p | 2.66 p | 2.63 p | 7.90 p | 5.24 p / 5.26 p |
| EU (Eurostat H2 2025: EUR 0.2896; gas EUR 0.11 approximate) | 8.69 c | 3.67 c | 2.90 c | 8.69 c | 5.02 c / 5.79 c |
| US (EIA July 2026: 18.31 c; gas 5 c approximate) | 5.49 c | 1.67 c | 1.83 c | 5.49 c | 3.83 c / 3.66 c |
Against a resistive heater (a bedroom panel, a US baseboard) the mining heat is free and every IGN earned is profit. Against a boiler or a heat pump the card must earn about 5.3 p an hour in the UK.
| Network hash | IGN per hour, 100 MH/s card at 100 IGN a block | at USD 0.005 | at 0.02 | at 0.10 |
|---|---|---|---|---|
| 100 GH/s | 360 | USD 1.80 | 7.20 | 36.00 |
| 1 TH/s | 36 | 0.18 | 0.72 | 3.60 |
| 10 TH/s | 3.6 | 0.018 | 0.072 | 0.36 |
So at 1 TH/s and USD 0.02 a 5090-class card earns 72 US cents (about 55 p) an hour and heats for 7.9 p: a heater that pays. At 10 TH/s and USD 0.005 it earns 1.8 cents and the heat costs 5.3 p more than gas: a heater that costs 3.9 p an hour net, which is still under the resistive panel it replaces in a room without a radiator. The honest sentence for the app: "In heat mode your card is an electric heater that also earns; whether it beats your boiler depends on the network and the price, shown live."
**Game theory.** None on the chain: a heat-mode miner is a miner with a schedule. One effect to name: seasonal hash. If heat mode becomes a large share of hash, winter hash rises and summer hash falls in the northern hemisphere; the DAA absorbs it, and the 30-day weight window means a summer departure of heat miners is a slow slide, not a departure event (the 10 percent per hour rule is not touched by a thermostat that ramps over weeks).
**Hostile review (Monero voice).** "A thermostat in a miner is a feature every miner GUI has had since 2014 (approximate: temperature targets in miner software). Call it heat mode if it sells; it changes nothing about the chain." Correct.
**Cost and gate.** App feature, 6 hours: a target-temperature input, the schedule, a sensor source (the OS's, or the card's own temperature as a proxy with a stated error), the live "earns X, heats Y, your boiler would cost Z" line from the tariff the user enters (phone-app 4.1 already has the tariff field). Gate: a room sensor loop on PC 1 holds a set temperature within 1 degree over four hours while the hash rate follows the duty cycle, logged.
**Per tier.** An 8 GB card at 150 W is a 150 W heater (the small-room case); a 5090 at 326 to 575 W (the ladder page's TGP range) is a large-room heater; a rig is a space heater that should not be in a bedroom; a pool user's duty cycle shows as a share-rate pattern the pool sees; macOS: the M5 Max at low watts is a poor heater; Windows and Linux alike.
**Verdicts.** Cryptographer: do now (no protocol content). Consensus engineer: do now, 6 hours. The miner: do now (the one feature a home miner in a cold flat asks for first; the number line must show when it loses to gas). Economist: do now, with the tariff line mandatory so nobody reads "free heat".
---
## 6. Phone-verifiable everything
**What remains after finality-in-proof and the WASM verifier (horizon rank 19).** Finality-in-proof gives 494 B of public values that say "locked at checkpoint i by x of y weight" under one proof; rank 19 gives the Groth16 or Plonk wrapper verified in a tab. What is left is the last mile: carrying that object with no network, and a "verify this block" link on the explorer.
**Prior art.** Mina (2021, approximate): a constant-size recursive proof of the whole chain, verified on a phone, with proof-of-stake under it. zkSync's block proofs on Ethereum (2023, approximate): verified by a contract, not a phone. Helios (a16z, 2022): a light client in WASM, trust rooted in a weak-subjectivity checkpoint. No proof-of-work chain has a phone-verifiable finality object; after finality-in-proof Igneum does, and the QR is only packaging.
**The object (model, section D).** Groth16 proof 260 B (SP1 docs) + public values 494 B + verifying-key id 32 B = 786 B. A version 40 QR at level L holds 2,953 B; a version 25 at level M about 1,000 B (approximate). So one QR carries the proof with room for a block hash and a receipt path of up to about 2 KB, and a phone with the pinned verifying key verifies it with no network: one bn254 multi-pairing, of the order of 2 to 5 ms native on a phone (approximate; Helios and the xycloo WASM demos are the order-of-magnitude anchors, 10 to 50 ms in WASM, frontier 3.4). The URL form is the same bytes base64 in a fragment, 1,048 characters, under every browser's limit.
**What the phone learns with no network.** That some chain with this chain id, under this aggregator program, had checkpoint i locked by x of y weight, with state root R and history root H, and (with the receipt path) that transaction T is in a block at or below the lock. What it cannot learn offline: that this is the LATEST lock (staleness: the `lock_daa` field lets it show the age against its own clock, labelled "age by your clock").
**The wrapper's cost on a 5090.** SP1's docs give PLONK as about 1 min 30 s longer than a compressed proof and Groth16 as the recommended on-chain form at 260 B; the wrap runs on the CPU in gnark whatever the GPU (approximate, from memory of SP1's wrapper architecture). So the wrap is not per segment (8 s): one wrapper machine wraps one proof per 90 s, and the chain's "latest wrapped proof" is 38 segments behind the tip at a 300-s cadence or 8 behind at 60 s with two wrapper machines (model, table D). The measurement the design needs is the one frontier 3.4 names (R4): wrap the pinned aggregator proof on a 24 GB fleet card and the box's CPU, record seconds and RAM. Expected, approximate: 60 to 180 s and 16 to 32 GB of RAM.
**The explorer link.** "Verify this block" on the explorer renders the QR and the URL for the newest wrapped proof whose history covers the block, plus the block's MMR path; the tab verifies it with rank 19's WASM verifier and shows the milliseconds. 4 hours once rank 19 lands.
**Game theory.** A forged QR fails verification; a stale QR shows its age; a QR from another chain id is refused. A soundness bug in SP1 forges a lock on the phone and not on the chain (full nodes verify the BLS certificate natively, finality-in-proof 5.1), which is the stated light-client row.
**Hostile review (Kaspa voice).** "A QR that says 'locked' with no network says 'locked as of when the QR was made'. Say the age in big letters or you will have people paying against last week's lock." Correct; the age line is in the design.
**Cost and gate.** 8 hours (QR and URL packing 2, the phone verify call on the shared `igneum-light` engine 4, the explorer link 2) plus rank 19's 16. Gate: a phone in airplane mode scans a QR printed from the explorer and shows "locked at checkpoint i, x percent of weight, age 4 minutes by your clock, verified in N ms"; a QR with one byte changed is refused.
**Per tier.** Holders: a proof in their pocket. Miners: their node serves the wrapped proof (section 3). Rollup customers: the same 786 B is what their bridge verifies. Node operators: one wrapper machine per network at a 300-s cadence (a box, not a card).
**Verdicts.** Cryptographer: do now after rank 19 (the first offline-verifiable PoW finality). Consensus engineer: do now (nothing in consensus). The miner: prototype (nice, not what miners ask for). Economist: do now (the cheapest public proof of the phase-two claim; the wrapper machine is one box).
---
## 7. More candidates, generated and judged
Twelve more. The first four are this lane's own (7.1 to 7.4); the rest are the brief's list, judged.
### 7.1 A weight-backed peer directory in the coinbase (this lane's candidate)
**The idea.** A block producer may opt in to carry its node's reachable address (IPv6 plus port, 18 B) in its coinbase extra data, signed by the vote key the header already names. The chain becomes its own seed list: a fresh client draws its outbound peers from the last 30 days of carried addresses, weighted by the carrying keys' W2 weight. No DNS seed, no shipped seed list beyond genesis peers, no operator.
**Prior art.** Bitcoin's DNS seeds and `addr` gossip (2011 onward, approximate); Ethereum's ENR and discv5 (2019, approximate); Kaspa's dnsseeder (approximate); the eclipse attack paper (Heilman, Kendler, Zohar, Goldberg, USENIX Security 2015) and its address-bucket fixes. No chain this lane knows writes reachable addresses into blocks under the producer's key with weight-weighted draws. New in form; the pieces (addr gossip, weighted sampling) are old.
**Mechanism.**
| Item | Rule |
|---|---|
| Object | `IGNA`-style section: `0x05 ‖ ip16 ‖ port2`, opt-in, at most one per block, signed by the header's vote key (the key reveal already proves possession) |
| Directory | every node keeps the last window's entries keyed by vote key hash (one address per key, newest wins) |
| Draw | a client picks outbound peers by the key's W2 weight; keys under dust are not drawn |
| Bytes | 18 B per block = 1.56 MB a day on every node (model, section E); 30 days at most 2.6 M entries, far fewer after de-duplication by key |
**Game theory (model, table E).** An attacker with share a of the 30-day weight lists share a of the directory. With 8 outbound peers drawn by weight, the probability every peer is the attacker's is a^8: 2.6e-6 at 20 percent, 1.8e-4 at 34 percent, 4.6e-3 at 51 percent; with 16 peers 6.6e-12, 3.2e-8, 2.1e-5. Against this, a DNS seed is one operator and a shipped list is one release key. The attack that remains: listing honeypot addresses under honest-looking keys costs the attacker 30 days of mining per key, the same bound as every other weight-backed thing on this chain. Griefing: a producer lists a victim's address to draw traffic to it; bounded by one address per key per block and the signed key, so the lister is named on chain.
**Hostile review (Kaspa voice).** "Your reachable miners are the rigs and the seeds; home miners are behind NAT and will list nothing or list a dead address. The directory is a list of rigs weighted by rigs, which is the thing you said you wanted to avoid (frontier 3.8's Kaspa attack). Also a 30-day-old address is a dead address." Answer: the client draws from the newest entries first with the weight as the tie-break, a liveness probe before use is the ordinary `version` handshake, and the rigs-weighted list is still a list of parties that mined 30 days of public blocks rather than one DNS operator. The NAT point stands and is the measurement.
**Cost and gate.** 10 hours: the coinbase section and signature check (3), the directory and the weighted draw in the node (4), the client's use in Ember verify mode and the phone (3). Gate: a fresh node with no seed list and genesis peers only reaches 8 outbound peers from the directory on the fast-time network; an eclipse harness with a 34 percent attacker listing 34 percent of addresses eclipses the fresh node in under 0.1 percent of 1,000 starts (expected 1.8e-4 at 8 peers).
**Per tier.** Home miner: opt-in, off by default (NAT); a rig and a seed node opt in; a pool node opts in; the phone and Ember verify mode gain a seed list with no DNS; no card, OS or vendor difference; node operators store 1.56 MB a day.
**Verdicts.** Cryptographer: prototype (a weight-backed seed list is the right shape; measure the NAT fraction). Consensus engineer: prototype (10 hours, nothing in fork choice). The miner: watch (home miners will not opt in; rigs will; fine). Economist: prototype (removes one operator from the trust row for 1.56 MB a day).
### 7.2 Sign-in with Igneum: 30 days of public work as a login (this lane's candidate)
**The idea.** A vote key signs a challenge to prove its W2 weight to a third party: a rental marketplace, a forum, a faucet, an airdrop-free allowlist. The verifier reads the weight from any node or the finality-in-proof public values. Sybil cost is 30 days of mining per identity.
**Prior art.** Hashcash (Back, 1997): proof of work as an anti-spam stamp. Sign-In with Ethereum (EIP-4361, 2021): a signed message as a login. Proof-of-humanity and Gitcoin Passport (2021 onward, approximate): social Sybil resistance. No chain has a non-transferable, work-earned weight per key to sign with; Igneum does.
**Game theory.** A key's weight is worth its 30 days of pool income (work-stake section 5: 2,793 IGN for an 8 GB card at 100 GH/s), so lending it to a login is lending a reputation that cannot be split without halving each half. A marketplace that gates on weight gets a Sybil cost it cannot buy elsewhere. The attack: a key used as a login is a key whose secret is on a machine that talks to websites; the pool spec's one-signer rule (9.6 item 3) and the equivocation strip mean a stolen key is burned by its thief in one double vote. The login must therefore be a delegated session key signed once by the vote key, never the vote key online.
**Hostile review (Monero voice).** "You are building an identity out of a mining key. Miners do not want identities; that is why they mine." Answer: opt-in, delegated, and the first customer is the rental escrow of frontier 3.13, which already needs the key.
**Cost and gate.** 6 hours (the delegation message, the verifier library in `igneum-light`, an Ember button). Gate: a web page verifies a delegated signature against a node's weight for one key and refuses a key under dust.
**Per tier.** Any key above dust (100 blocks a window; 3.86 MH/s at 100 GH/s) can sign in; an 8 GB card qualifies at every network size up to about 440 GH/s (where 17 MH/s falls under dust, arithmetic on work-stake section 5); below that, nothing.
**Verdicts.** Cryptographer: watch (the delegation design is the whole risk). Consensus engineer: watch (not consensus). The miner: watch. Economist: prototype only with the rental escrow as the first user.
### 7.3 Public timestamping on the proof chain (this lane's candidate)
**The idea.** Any hash posted in an Igneum transaction is, 60 to 93 s later, inside a certified checkpoint and, after the segment proof, inside a 786 B offline-verifiable object (section 6). OpenTimestamps (Todd, 2016, approximate) does this on Bitcoin with hours of latency and a Merkle aggregator; Igneum does it with the lock latency and a proof a phone verifies.
**Game theory.** None: a transaction with a hash. The base fee burns; the priority fee pays. The product is the receipt path in the QR.
**Cost and gate.** 4 hours (a contract that emits the hash in a log, the receipt path in the explorer link of section 6). Gate: a timestamp verified offline on a phone from a QR.
**Verdicts.** All four: do now once section 6 lands; it is section 6's first use. The economist: a product with a fee a user pays, which is the kind the utility lane wants.
### 7.4 Hash-rate futures as an app (this lane's candidate, judged against ruling)
**The idea.** Braidpool's stated purpose: a miner sells its future shares forward for cash now. On Igneum a miner could sell its next window's pool income (the work-stake bond) forward.
**Why it dies.** A forward needs a counterparty and collateral; the collateral is a coin balance posted by the seller or buyer, which is a coin bond, which is refused by ruling for anything the protocol touches. As an app between consenting parties with their own escrow it is allowed and the chain is indifferent. Prior art: Braidpool (in development), NiceHash (2014, an operator market). Verdict: never in protocol; watch as a third-party app. 0 hours.
### 7.5 Finality as a service for other PoW chains
**The idea.** Another PoW chain posts its block hashes into Igneum and treats the Igneum lock as a checkpoint; its clients refuse reorgs below the last anchored, locked hash. Igneum relies on nothing; others relying on Igneum is allowed by ruling.
**Prior art.** Komodo dPoW (2018, approximate; the academy page 404'd): notary nodes write a chain's block hash into Bitcoin every 10 minutes (approximate) and protected chains refuse reorgs below it; VeriBlock Proof-of-Proof (2019, approximate; veriblock.org: "securing 1 chain", market cap USD 9 M); Babylon (Tas, Tse, Gai, Kannan, Maddah-Ali, Yu, 2022, IEEE S&P 2023: PoS chains checkpoint to Bitcoin; stake withdrawal from weeks to under 5 hours). Igneum's difference: the anchored chain gets a 90-s lock instead of Bitcoin's hour, and an offline-verifiable proof instead of an SPV path.
**Game theory.** For Igneum: none; an anchor is a transaction. For the anchored chain: its safety becomes Igneum's finality, which pauses whenever under two thirds of weight signs (spec 03 3.7); an anchored chain must fall back to its own PoW during a pause and say so, which Babylon's design also requires of its consumers. A hostile Igneum majority cannot forge an anchor (it would need two thirds of weight to lock a false chain) but a third of weight can pause anchoring. Market (model, section G): at Komodo's cadence (144 anchors a day) the fee is 0.73 IGN a day, under one cent at any listed price. Revenue to Igneum: nothing material; standing: a product no PoW chain offers with proof-carrying finality.
**Hostile review (Kaspa voice).** "Who are the customers? Komodo's dPoW protected a handful of Komodo-family chains and VeriBlock secures one chain worth USD 9 M. Small PoW chains that fear 51 percent (ETC, BTG, VTC in 2018 to 2020) chose checkpoints from their own developers over paying anyone." Correct; the demand is the gate.
**Cost and gate.** 16 hours: an anchor contract (4), a client library that reads the lock and the proof for an anchored hash (8), a reference patch for one open-source PoW node (4). Gate: one outside chain's testnet runs the patch for a week and refuses a staged deep reorg below an anchored lock.
**Per tier.** Nothing changes for any Igneum miner or holder; an anchored chain's miners get a 90-s checkpoint they did not vote for, which their community must accept (the Komodo precedent: accepted by chains that chose it).
**Verdicts.** Cryptographer: prototype (sound, and the first external use of the lock). Consensus engineer: watch (demand first). The miner: watch (no miner cares). Economist: watch (USD 0.004 a day per customer at the floor is standing, not income).
### 7.6 The hourly program as a standing public hardware benchmark with a leaderboard
Frontier 3.16 (do now, 10 hours) publishes the corpus; the leaderboard is the product on top: per card model, per vendor, per driver, the median rate and joules per hash across the hour's variants, from the fleet library and opt-in Ember submissions, with the bit-exact fingerprint per entry. Prior art: Geekbench (2007, approximate), hashrate.no and WhatToMine (2018 onward, approximate) as operator tables; none continuous on a random kernel stream. New as a continuous random-kernel benchmark. Game theory: a submitter lies about its rate; the fingerprint proves bit-exactness not speed, so self-reported rates are labelled and the fleet's measured rows are the reference tier. Cost 8 hours on top of 3.16. Gate: a public page with the eleven measured cards (prover-tiers-real-cards.md) as the reference tier and opt-in rows beneath. Verdicts: do now (all four; the miner: "a leaderboard is the first thing a mining YouTuber screenshots").
### 7.7 Proof of unique card: count machines, not keys
Dead, and the reason is the design's own: nothing in consensus counts nodes, keys or cards (spec 3.1 W6, ledger F17), so a count of machines would be a Sybil surface the design removed on purpose; and a chip emulates any fingerprint it has been shown (frontier 4.3's Monero attack). What the design does count is blocks, and a card's blocks are its weight. Verdict: never. 0 hours.
### 7.8 Shard proving as the on-ramp: a proving-only key earning pool income without a card
Dead by the sortition rule: shard assignees are drawn by W2 weight (spec 7.2 step 2); a key with no blocks has no weight and is never drawn. What a proving-only key can do today: claim shards after the exclusive window (spec 7.2 item 4) and prove external jobs under the pool protocol's bonded key route (work-stake section 5, the prover row). That is the on-ramp and it exists. Verdict: never as a rule change; the two existing routes stand. 0 hours.
### 7.9 Miner-signed release: 95 percent of weight signs the release hash
Compare horizon rank 13 (reproducible-build attestations, N of M builders, 12 hours). A weight signature says "we RUN this hash", not "we BUILT it", and running is what the 95 percent class signal already measures (the object byte in the header version). So the idea is the P2 signal applied to a binary hash instead of a class byte: a header bit per release. Prior art: BIP9's version bits (2015) for rules, not binaries; no chain signals binary hashes (approximate). What it adds: a chain-readable "share of weight on release X" that Ember can show beside rank 13's "N builders reproduced X". Cost 4 hours (a release-hash field in the coinbase, tallied by the explorer, no consensus effect). Game theory: lying costs nothing and buys nothing; it is a statistic. Verdict: watch, fold into rank 13's display. Cryptographer: watch. Consensus engineer: do as a coinbase field, 4 hours. The miner: watch. Economist: watch.
### 7.10 An energy-price oracle from miners' own signals
**The idea.** Each producer carries its electricity price in its coinbase; the window's weighted median is the chain's energy price, free of any oracle operator.
**Prior art.** Chainlink and the oracle networks (2017 onward, approximate); frontier 3.5's miner-voted dials (Ethereum's gas-limit vote, geth `VerifyGaslimit`); no PoW chain carries a price field (approximate).
**Game theory.** A field nobody is paid for and nobody is punished for lying in is noise; a field that feeds a price (the job reserve of horizon rank 7, "measured proving electricity per pgas at the published settlement rate") is a field miners overstate, bounded only by the customer's bid, which rank 7 already makes the price. So the oracle is either noise or a lever on the job price that the bid neutralises. The honest use is statistical: the miner community lead's hardware-economics model wants real tariffs, and Ember's opt-in telemetry (the tariff field of phone-app 4.1) gives them off-chain with no consensus bytes.
**Verdict.** Never in consensus; an opt-in Ember statistic. 2 hours for the telemetry line. All four personas: never in protocol.
### 7.11 A first-block bonus per new key, Sybil-bounded by dust
**The idea.** A key's first block above dust pays a bonus B, to welcome newcomers; the signing bonus of vote-or-burn exists, so this would be the second bonus.
**Game theory (model, section F).** Dust is 100 blocks a window. A 10 percent miner makes 259,200 blocks a window and can keep 2,592 keys above dust, each collecting B once: at B = 100 IGN that is 259,200 IGN a window, 1 percent of its subsidy, for free (weight and sortition are per block, so the split costs it nothing but its own vote's convenience; the pool spec's one-key rule is a client default, not a consensus rule). A bonus large enough to matter to a newcomer (10 blocks, 1,000 IGN) is a 10 percent raise for every miner willing to run 2,592 keys. The dust bound makes the Sybil expensive in KEYS and free in HASH, and keys are free. Verdict: never. 0 hours. The miner: "an instamine with extra steps".
### 7.12 A cross-vendor parity bounty
Dead by ruling (no device bounty): a payment conditioned on a card model is a device bounty whatever it is called. What the design does instead is measure (the eleven rented cards, the ladder's per-rung 5 percent rule) and publish. Verdict: never. 0 hours.
### 7.13 In-protocol insurance against reorgs for exchanges
**The idea.** An exchange that credited a deposit later reversed by a reorg is made whole from a protocol pool.
**Prior art.** None shipped in any protocol (this lane found no primary page; approximate). Off-chain: exchange confirmation policies; Nexus Mutual-style cover for contracts (2019, approximate), not for reorgs.
**Why it dies.** Who pays? A protocol pool is either emission (a transfer from miners to exchanges, which the miner persona rejects on the Decred and Ethereum precedents in vote-or-burn section 2) or the proving pool (a transfer from provers, who did nothing wrong). The design's own answer is stronger than insurance: a certified checkpoint cannot be reversed (51-percent.md section 2), the four-state rule credits on "finalised" (ledger P17), and the exchange guidance says confirm at the lock or at 12 hours during a pause (horizon rank 16). Insurance is only wanted where finality is paused, and during a pause the only reorg-capable party is a hash majority with no slashable bond, by ruling. Verdict: never; the guidance is the product. 0 hours.
### 7.14 Pause insurance from the proving pool
Dead: it pays the wrong people or nobody. During a pause the silent third earns its subsidy (51-percent.md: "free to hold while silent"); redirecting pool income to the signing keys is the signing bonus's job (8 of 80 points) and to holders is impossible (no mechanism pays holders). Vote-or-burn priced the pause at 3,103 to 6,206 IGN an hour at 34 percent silent and found a deposit worth attacking covers either; LEAVE and weight-gated fork choice close the line. Verdict: never. 0 hours.
### 7.15 Proof of latency: rewarding low-latency relays
The arXiv search for "proof of latency" this morning returned five unrelated papers and none on relay rewards; FIBRE (2016) relays unpaid. Timing is unverifiable in consensus (section 1.4) and the DAG already pays for latency in blue blocks (under 2 percent red at 1 block/s, run B). A relay reward would need a clock and a Sybil-proof receipt, and it has neither. Verdict: never. 0 hours.
---
## 8. Verdict table
Ranked. At most three "do now" and three "prototype"; the rest "watch" or "never" with the line that killed them. Persona order: cryptographer / consensus engineer / the miner / economist.
| Rank | Candidate | Prior art (name, year) | New? | Survives its game (bound) | Hostile review verdict | Hours | First gate | Four verdicts | Recommendation |
|---|---|---|---|---|---|---|---|---|---|
| 1 | 6 Phone-verifiable proof in a QR or URL, offline, plus the explorer link | Mina 2021 (approx.), Helios 2022, zkSync block proofs 2023 (approx.) | the offline PoW finality object is new | yes (a forged QR fails; staleness shown by `lock_daa`) | "show the age in big letters": accepted | 8 (+16 rank 19) | phone in airplane mode verifies a printed QR, refuses a one-byte change | do now / do now / prototype / do now | **do now** |
| 2 | 5 Heat mode in Ember | Heatbit 2022, 21energy (Austria), Qarnot 2010 (approx.) | new only as a chain client feature | yes (a schedule is a schedule; seasonal hash absorbed by the DAA and the 30-day window) | "every miner GUI has a thermostat": accepted | 6 | set temperature held within 1 degree for 4 h on PC 1 while hash follows the duty cycle | do now x4 | **do now** (UK break-even 5.3 p an hour against gas or a heat pump; free against a resistive panel) |
| 3 | 3 Miners' nodes serve the 786 B proof to phones (Ember line, unpaid) | Portal Network 2021 to 2026 (unrewarded), Helios 2022, Mina snarkers 2021 (approx.) | no | yes (a lie fails verification; eclipse bounded by N of M pins) | "not a service you price": accepted | 4 (+20 frontier 3.8) | a phone on cellular shows "locked, voter set verified" from a miner's node | do now x4 | **do now** |
| 4 | 7.1 Weight-backed peer directory in the coinbase | DNS seeds 2011, discv5 2019, Heilman 2015 (approx.) | new in form | yes: eclipse at 34 percent of weight 1.8e-4 with 8 peers, 3.2e-8 with 16 (model E) | "a list of rigs weighted by rigs; NAT": partly accepted, the NAT fraction is the measurement | 10 | fresh node with genesis peers only reaches 8 outbound from the directory; 34 percent attacker eclipses under 0.1 percent of 1,000 starts | prototype / prototype / watch / prototype | **prototype** |
| 5 | 4 Verifiable payout contract for existing pools (SmartPool shape) | SmartPool 2017; Ocean 2023 (approx.) | no | yes (a dropped share is provable from the member's log) | "P2Pool sidechain if you want no operator": accepted as the alternative | 16 | a member proves a dropped share on the fast-time network and is paid; 32 B per round on chain | prototype x4 | **prototype** |
| 6 | 7.5 Finality as a service for other PoW chains | Komodo dPoW 2018 (approx.), VeriBlock PoP 2019 (approx.), Babylon 2022 | the 90-s proof-carrying anchor is new | yes for Igneum (an anchor is a transaction); the anchored chain inherits Igneum's pauses | "who are the customers": demand is the gate | 16 | one outside testnet refuses a staged deep reorg below an anchored lock for a week | prototype / watch / watch / watch | **prototype** (demand-gated) |
| 7 | 7.6 Hardware leaderboard on the program corpus | Geekbench 2007, WhatToMine 2018 (approx.); frontier 3.16 | new as a continuous random-kernel benchmark | yes (self-reported rates labelled; the fleet's rows are the reference tier) | none | 8 (+10) | public page with the eleven measured cards as the reference tier | do now x4 | watch (frontier 3.16 is already "do now"; this is its page; the cap of three "do now" is spent) |
| 8 | 7.3 Public timestamping on the proof chain | OpenTimestamps 2016 (approx.) | the offline-verifiable receipt is new | yes | none | 4 | a timestamp verified offline from a QR | do now x4 | watch until rank 1 lands, then 4 hours |
| 9 | 7.2 Sign-in with Igneum (delegated weight as a login) | Hashcash 1997, EIP-4361 2021 | new (work-earned, non-transferable weight) | yes if delegated (a vote key online is a key a thief burns) | "miners do not want identities": opt-in | 6 | a page verifies a delegated signature against a node's weight; dust refused | watch / watch / watch / prototype | watch (first user: the rental escrow) |
| 10 | 7.9 Miner-signed release hash in the coinbase | BIP9 2015; horizon rank 13 | no | yes (a statistic) | fold into rank 13 | 4 | the explorer shows share of weight per release hash | watch / do / watch / watch | watch |
| 11 | 1.3 and 1.5 Proof of serving or state availability as a reward slice | Filecoin PoSt 2020, Arweave SPoRA 2021 (approx.), PeerDAS 2024 | the miner-key reward is new | no: outsourced in 108 ms; self-answered under class v5 | "pays for what the lottery compels" | 0 (4 for the unpaid RPC) | | never x4 | never: the unpaid RPC (new-pow rank 6) is all that survives |
| 12 | 2 x of 80 points conditional on serving | as 11 | no | no (same bounds; a second liveness bonus on the signing bonus's event) | "merge or drop" | 0 | | never x4 | never |
| 13 | 4 In-protocol pool (shares in blocks) | FruitChains 2016, P2Pool 2011, Monero P2Pool 2021, Braidpool (in development) | no | yes on incentives (withholding self-defeating), no on cost: 14.6 to 146 GB a day and 5 to 50 cores per node at 10,000 to 100,000 miners on a 10-s share | "we built a sidechain for this reason" | 0 | | never x4 | never in protocol |
| 14 | 1.2 Proof of following | Verthash 2021 (approx.), class v5 2026 | in form only | yes, by doing nothing new | "the root already commits to the chain" | 0 | | never x4 | never: the epoch seed plus class v5 is proof of following |
| 15 | 1.4 Proof of propagation receipts | FIBRE 2016 (unpaid) | no | no (time unverifiable; receipts Sybil-free; 94 to 376 MB a day) | "GHOSTDAG is a proof of propagation" | 0 | | never x4 | never |
| 16 | 7.10 Energy-price oracle from miners | Chainlink 2017, frontier 3.5 | no | no (noise, or a lever the bid neutralises) | | 2 (Ember telemetry) | | never x4 (in protocol) | never; opt-in statistic |
| 17 | 7.11 First-block bonus per key | the signing bonus (vote-or-burn) | no | no: a 10 percent miner collects it 2,592 times a window (model F) | "an instamine with extra steps" | 0 | | never x4 | never |
| 18 | 7.13 Reorg insurance for exchanges | none shipped (approx.) | yes | no (no slashable payer by ruling; the lock is the product) | | 0 | | never x4 | never |
| 19 | 7.14 Pause insurance from the proving pool | vote-or-burn's pricing | no | no (pays the wrong people) | | 0 | | never x4 | never |
| 20 | 7.15 Proof of latency | none found (arXiv, 7 Oct 2026) | yes | no (no consensus clock) | | 0 | | never x4 | never |
| 21 | 7.7 Proof of unique card | frontier 4.3 | no | no (nothing counts cards by design; a chip emulates a fingerprint) | | 0 | | never x4 | never |
| 22 | 7.8 Proving-only key earning pool income | spec 7.2 | no | dead by the sortition rule; open claims and the pool route exist | | 0 | | never x4 | never |
| 23 | 7.12 Cross-vendor parity bounty | | | dead by ruling (device bounty) | | 0 | | never x4 | never |
| 24 | 7.4 Hash-rate futures | Braidpool, NiceHash 2014 (approx.) | no | needs a coin bond: dead in protocol | | 0 | | never (protocol) x4 | never in protocol; a third-party app is the chain's indifference |
Three "do now": ranks 1, 2, 3 (34 hours in all, plus the 36 of rank 19 and frontier 3.8 they sit on). Three "prototype": ranks 4, 5, 6 (42 hours). Everything the brief hoped was a protocol invention in sections 1, 2 and 4 is dead on a number this lane ran: 108 ms (the outsourcing fetch), 0.61 to 76.5 GB a day (challenge answers), 14.6 to 146 GB a day and 5 to 50 cores (in-protocol shares).
---
## 9. The honest answer
Igneum's revolution is the combination already built, not any one new item. The pieces that exist in code or on a branch today and that no shipped proof-of-work chain has together: a random-program GPU hash whose dataset is the chain's own state (class v5, hash rate unchanged at 63.08 MH/s, verifier +0.11 to 0.21 ms), miner-only finality by 30 days of blue blocks with no stake (a lock 63 to 93 s after a checkpoint; 51 percent never reaches two thirds while honest miners mine), that finality carried inside the execution proof as 494 bytes a phone verifies (finality-in-proof), a bond for proving jobs made of 30 days of public work and no coin (work-stake: 2,793 IGN at risk for an 8 GB card at 100 GH/s against a 0.0015 IGN coin bond), a tail that keeps a 24-hour attack at about twelve days of emission in every year, and a pool protocol in which the operator holds no key and no vote.
This lane tested fourteen candidates for the next thing and found two small ones worth building now (the offline proof in a QR, 8 hours, and heat mode, 6 hours), one Ember line (miners' nodes serve the proof, 4 hours), and three prototypes (a weight-backed peer directory that bounds an eclipse at 1.8e-4 for a 34 percent attacker, a verifiable payout contract for pools, and finality as a service for other chains). Every candidate that would have changed consensus died on a measured number: proof of serving on a 108 ms fetch, in-protocol shares on 14.6 GB a day, propagation receipts on the absence of a clock. The next genuinely new thing is the first offline-verifiable proof-of-work finality object in a user's pocket, and it is packaging on what is already built.
---
## 10. Three headline findings for the coordinator
1. Every "hashing useful to the chain" variant beyond class v5 is dead on one number: a key with no state answers an availability challenge in about 108 ms over a 100 ms link, so any deadline over one block makes the proof "someone served", and the reward slice it would gate (2 to 8 of the 80 points, 17 to 69,120 IGN a day by key size) pays for what the lottery already compels.
2. An in-protocol pool is FruitChains (2016) and it costs every node 14.6 GB a day and 5 cores at 10,000 miners on a 10-s share (146 GB and 50 cores at 100,000), so the finished form is the shipped pool v0 plus a verifiable payout contract (SmartPool 2017 shape, 16 hours, 32 B per round on chain).
3. The three things worth doing now total 18 hours and change no consensus rule: an offline-verifiable 786 B finality object in a QR (260 B Groth16 + 494 B public values + 32 B key id, under a version-40 QR's 2,953 B), Ember heat mode (a 300 W card breaks even against a UK gas boiler or COP-3 heat pump at 5.3 p an hour earned, and is free against a resistive heater), and every miner's node serving that proof to phones.
---
## Sources (accessed 7 October 2026 unless stated)
Project files: `docs/analysis/horizon-2026-10.md`; `docs/analysis/horizon/frontier.md`; `docs/analysis/horizon/new-pow.md`; `docs/analysis/class-v5-stored-state.md` (branch class-v5); `docs/analysis/finality-in-proof.md` (branch fin-proof); `docs/analysis/work-stake.md` (branch work-stake); `docs/analysis/tail-emission.md`; `docs/analysis/vote-or-burn.md`; `docs/design/latency-ladder.md`; `docs/analysis/51-percent.md`; `docs/plans/pool.md`; `docs/spec/09-pool-protocol.md`; `docs/spec/10-light-client.md`; `docs/design/phone-app.md`; `docs/bench-log.md` (lines 170, 230, 685, 873 to 877, 1934, 2582 to 2635); `.claude/agents/*.md`. Model: `/private/tmp/claude-501/-Users-joshm/cd75457f-4858-4f86-9634-7481ee056b7b/scratchpad/mission-invent/invent_model.py` and `out.md`.
Primary pages fetched (WebFetch; the session's WebSearch budget was spent before this lane started, so every check is a direct fetch of a known primary page):
- FruitChains: A Fair Blockchain, Pass and Shi, 2016: https://eprint.iacr.org/2016/916
- SmartPool: Practical Decentralized Pooled Mining, Luu, Velner, Teutsch, Saxena, 2017: https://eprint.iacr.org/2017/019
- Monero P2Pool (SChernykh): https://github.com/SChernykh/p2pool
- Braidpool: https://github.com/braidpool/braidpool
- EIP-7594 PeerDAS (2024): https://eips.ethereum.org/EIPS/eip-7594
- Portal Network: https://ethportal.net/
- FIBRE: https://bitcoinfibre.org/
- Helios: https://github.com/a16z/helios
- Heatbit: https://www.heatbit.com/
- 21energy: https://21energy.com/
- Filecoin storage mining and WindowPoSt: https://spec.filecoin.io/systems/filecoin_mining/storage_mining/
- SP1 proof types (Groth16 about 260 B, PLONK about 1 min 30 s longer than compressed): https://docs.succinct.xyz/docs/sp1/generating-proofs/proof-types
- Ofgem energy price cap unit rates, 1 October to 31 December 2026 (26.32 p electricity, 7.97 p gas, direct debit, national average): https://www.ofgem.gov.uk/your-energy-supply/your-energy-bill/energy-price-cap-unit-rates-and-standing-charges
- EIA, average residential electricity price, July 2026 (18.31 cents per kWh): https://www.eia.gov/electricity/monthly/epm_table_grapher.php?t=epmt_5_6_a
- Eurostat, electricity price statistics, H2 2025 (EUR 0.2896 per kWh household): https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Electricity_price_statistics
- Babylon: Bitcoin-Enhanced Proof-of-Stake Security, Tas, Tse, Gai, Kannan, Maddah-Ali, Yu, 2022: https://arxiv.org/abs/2207.08392
- VeriBlock Proof-of-Proof: https://www.veriblock.org/
- arXiv search "proof of latency" (no relevant paper): https://arxiv.org/search/?query=%22proof+of+latency%22&searchtype=all
Pages that returned 404 this morning, so the item is labelled approximate in the text: Arweave yellow paper and mining guide (SPoRA), vertcoin.org Verthash page, Komodo dPoW academy page, Qarnot's Wikipedia page, Ofgem's cap-levels page (the unit-rates page above answered instead). Figures from memory are labelled approximate where they appear: Heatbit's 2022 launch, Qarnot's 2010 founding and 2013 QRad, Komodo's 2018 dPoW and its 10-minute cadence, VeriBlock's 2019 launch, Verthash's January 2021 activation, Mina's 2021 phone verification, EU and US gas prices, phone-side pairing times, SP1's Groth16 wrap time and RAM, Geekbench and WhatToMine years, the Heilman 2015 eclipse paper's venue.

View file

@ -0,0 +1,186 @@
# The Igneum Mission
Written 7 October 2026, morning UK, by the mission coordinator (branch `mission`, worktree `igneum-wt-mission`) on the project lead's order of the same morning, verbatim: "i dont want to get stuck in a loop here where we keep finding and adding features and security so im going to give you one last mission, deep deep dive into the past and look far into the future, what has been done, what hasnt been done, what has been started but not finished, what can we invent and what can we reinvent to honestly make the perfect gpu network that will be noticed as the revolution that everyone is waiting for."
This is the last research round. Its output is the closed list in section 2. After it the project stops researching and ships. Five lanes ran in parallel and each has its own file with sources and a verdict table: `past.md` (lane 1), `unfinished.md` (lane 2), `future.md` (lane 3), `invent.md` (lane 4), `reinvent.md` (lane 5). Every number below names its lane; the lane file names the source or the model. Hours are agent hours. Nothing on the live devnet was touched and no build or hash measurement was run for this document.
## 1. One page for the project lead
**What has been done.** Of 31 GPU-mined chains since 2011, 8 lost the GPU lane to a chip, 7 closed it by choice, 10 died on price or a rental attack; the 6 still GPU-only pay USD 0.22 to 0.71 a day per RTX 3080 (lane 1). In 20 miner posts the wants were hardware that keeps its value, income without a cliff, a fair supply. Igneum answers the supply in full (no premine, no fund, no fee to any team), the hardware with a measured 2.1x chip bound and the N ladder, the cliff with a monthly glide and a 1 percent tail. Finality by 30 days of blocks, proving as the reward, the leave item and the signing bonus are built or approved for the testnet genesis.
**What has not been done.** Nobody on those forums asked for finality, a DAG or proofs; they asked for a card that keeps its value, a bill that gets paid and a coin that sells. The front page leads with the hash, the earnings page shows £0.00, a fresh install opens with two operating-system warnings and ends its first hour without one number the miner came for, and no proving customer has signed, so the coin has Ergo's 2023 exposure: a thin market. These gaps are hours, not protocol.
**Started and not finished.** Three designs sit on branches: class v5 (the dataset is the chain's own state), finality inside the segment proof, work-stake (a bond of 30 days of work, no coin). Across the industry (lane 2), every useful-work scheme that passed cheap-verify did so by making the work useless, no pool without an operator exists on any chain but Monero, and every proof-of-work finality that held was a second validator set bought with coins. Lane 4 tested whether anything new in consensus beats these; each died on a number: proof of serving on a 108 ms fetch, in-protocol pool shares on 14.6 GB a day per node at 10,000 miners, propagation receipts on the absence of a clock, proof of following because the epoch seed plus class v5 already is one.
**What we invent.** One thing, and it is packaging on what is built: the first offline-verifiable proof-of-work finality object: 786 bytes in a QR a phone verifies in airplane mode, served by every miner's node. No PoW chain has put finality in a user's pocket. Beside it, two genesis bytes the future demands (lane 3): a signature-scheme byte with a key-succession slot, because a post-quantum vote at 8,192 voters costs 57 GB a day unaggregated and the flip must be signalled before a machine exists; and a cache-size rung on the ladder, because a 256 MB consumer cache is a 2 to 3x shortcut.
**What we reinvent.** The miner's first month. The 30-day vote window is a level system no chain has, and it is free: first block, 100 blocks for a vote, a signature in a checkpoint, 30 of 30 days, rank by weight, a signing streak. Every rung is a chain fact from one RPC; a renter cannot top it inside 30 days; no fund pays for it. Lane 5 priced the first month at about 35 hours: the Poisson count-up before the first block (an 8 GB card at 100 GH/s waits 1.6 hours expected), the block card, earnings in IGN first, the weight leaderboard, the hardware census. In a 105-post Reddit sample the miner's own posts rise highest ("my card paid for itself" at 777 times the room median against 66 for the network's milestone), so every shareable surface carries the miner's card, rank and days, never the project's number.
**The honest answer.** Igneum's revolution is the combination already built plus two new things: the finality object in the pocket, and the ladder shown everywhere. No shipped chain has the combination: a random-program GPU hash whose dataset is the chain, miner-only finality with no stake that 51 percent never reaches, that finality inside the execution proof, a work bond with no coin, a tail that holds a 24-hour attack at twelve days of emission in every year. Twelve items, about 290 agent hours, no new consensus rule beyond the three cut branches.
### Decisions owed from the project lead
The cryptanalysis entity and prize; the signing certificates (lane 5); the signed proving customer as a mainnet gate (lane 1); the H100 and A100 hash measurement on rented pods (lane 3).
## 2. The closed list
Twelve items, in build order. "In flight" names the lane or branch that holds it. Hours are the remaining agent hours; a gate is what must be true before the item is called done. Nothing is added to this list without removing something.
| # | Item | State | Hours | Gate |
|---|---|---|---|---|
| 1 | The testnet genesis re-cut as approved | in flight (ship lane) | 0 new | the go checklist |
| 2 | Finality in the pocket: finality in the proof, the 786 B object, every node serves it, the browser verifier | in flight (fin-proof) plus new | 68 | a phone in airplane mode verifies a printed QR and refuses a one-byte change |
| 3 | Class v5, the dataset is the chain, and nothing wider | in flight (class-v5) | 16 | the fast-time harness across a day boundary; Devnet 2 across a real day |
| 4 | Weight-gated deep fork choice before mainnet | in flight (horizon rank 4) | 16 | a 51 percent fresh-key fork from 15 min back refused by every honest node |
| 5 | Work-stake: the job bond made of 30 days of work | in flight (work-stake) | 24 | 1,000 posted jobs, every injected miss forfeits, zero honest forfeits |
| 6 | The ladder shown everywhere: the miner's first month | new (lane 5) | 35 | a Devnet 2 key walks every rung on screen; first share within 10 minutes in 9 of 10 fresh Windows installs |
| 7 | Heat mode, the region and price prompt, the cost-against-rent line | new (lanes 3, 4) | 10 | a set temperature held within 1 degree for 4 h on PC 1 while hash follows the duty cycle |
| 8 | Genesis forward-compatibility: the scheme byte, key succession, the cache rung | new (lane 3) | 10 | the digest test; a vote item with scheme 1 refused by every node until the signal |
| 9 | A second proof system on the active list and the one-third stop switch | new (frontier I4, lane 3) | 24 | 1,000 segments agree across both systems; one injected bad proof disagrees and pays nothing |
| 10 | The launch pack: gates and text, no protocol | new (lanes 1, 3, 5) | 15 | every gate line in testnet-go.md with its check |
| 11 | The pool finished: pool-0 with member keys at 1 percent, TLS, the share sidechain with no operator | new (lanes 2, 4, 5) | 60 | 100 members on the fast-time network paid by the coinbase rule from a share chain with no operator key; the first on a DAG chain |
| 12 | The weight-backed peer directory | new (lane 4, prototype) | 10 | a 34 percent attacker eclipses under 0.1 percent of 1,000 fresh starts |
### 2.1 The testnet genesis re-cut as approved (in flight, ship lane)
What it is: one cut with 18 decimals, `EmissionSchedule::TESTNET_1` (100 IGN a block, a monthly glide with a two-year half-life, a 90-day ramp from 10 percent, a 1 percent tail from year 11.4), and the switches on from genesis: proof verification in consensus, the leave item, the signing bonus at 1,000 bps, finality v3, the latency ladder at rung 0. the project lead approved it on 7 October 2026, 09:3x UK (ledger-decisions.md).
Why it is right: lane 1's verdict rows 4 and 5 (the cliff and the premine) are answered by it in full; lane 3's tail row holds to year 200.
Evidence: tail-emission.md one page; vote-or-burn.md section 5; ledger-decisions.md 7 October.
Cost: 0 new hours; the ship lane's own plan.
Gate: the go checklist (`docs/plans/testnet-go.md`); nothing mines until the word.
Order: first; every later item lands on this genesis.
### 2.2 Finality in the pocket (in flight on `fin-proof`, plus three new parts)
What it is: the weight table carried inside the recursive segment proof (W2 updated one mergeset per segment, the BLS certificate verified in the guest, 494 B of public values), then three parts this mission adds: a Groth16-wrapped proof as a 786 B object (260 B proof, 494 B public values, 32 B key id) in a QR or URL that a phone verifies offline; every miner's node serving the latest object by default (an Ember line, unpaid); and the WebAssembly verifier in the tab (horizon rank 19).
Why it is new: no proof-of-work chain has an offline-verifiable finality object; the closest shipped forms are Mina's recursive state proof (2021) and Helios's committee light client (2022), both online and neither over proof of work. Lane 4 section 6 and 3, persona verdicts do now, do now, prototype, do now.
Evidence: finality-in-proof.md sections 1 to 5 (level 1 of the blue-set check designed, level 0 in the prototype); the certificate half verifies in 58 to 68 ms warm in a browser (bench-log round 6); SP1 light verifier 0.032 s on a Mac core; a version-40 QR holds 2,953 B.
Cost: 40 for the fin-proof remainder (level 1 of 5.2, the cycle counts of section 6.1 on the box, the 5090 prover time on a pod), 8 for the QR object, 4 for the Ember line, 16 for the WASM verifier. 68.
Gate: a phone in airplane mode verifies a printed QR and refuses a one-byte change; "locked, voter set verified" on cellular from a miner's node; a block proof verifies in the tab under 500 ms on a laptop.
Order: second; it is the one invention and it needs the genesis of item 1 for the pinned aggregator id.
### 2.3 Class v5, the dataset is the chain, and nothing wider (in flight on `class-v5`)
What it is: each day's dataset built from the execution state at a reference block an hour before the day; a card without the state builds every item wrong. The branch widened it to a per-window refresh (section 2a of its page). This mission's ruling: no further widening. Lane 4 tested proof of following, serving, propagation and state availability as additions and found each dead on a number: a key with no state answers an availability challenge in about 108 ms over a 100 ms link, so any deadline over one block proves only that someone served; propagation receipts need a clock the DAG does not have; the epoch seed plus the state root already commit to the chain's recent blocks, so proof of following is class v5 by another name.
Why it is right: hash rate and watts unchanged within noise (63.083 against 63.088 MH/s, 205 to 208 W on a 4090), build +1.4 ms, verifier +0.11 to 0.21 ms per unit; it removes the f = 0 recompute chip as a category and the stateless pool miner.
Evidence: class-v5-stored-state.md; new-pow.md 5.2 and 6; invent.md sections 1 and 8 rows 11 to 15.
Cost: 16 (the 4090 rows owed in section 7, the exec snapshot wire version 2, the GPU hosts' leaf buffer, the spec text).
Gate: the fast-time harness crosses a day boundary with the roots agreeing on every node and the stateless node's miner at 0 accepted blocks; Devnet 2 across a real day boundary; then the 95 percent signal with a floor.
Order: third; it rides the class-signal machinery item 1 ships.
### 2.4 Weight-gated deep fork choice before mainnet (in flight, horizon rank 4)
What it is: a tip whose fork point is older than D (10 min of past-median time) is a fork-choice candidate only if the keys that built it hold at least a third of the weight table at the fork point.
Why it is right: lane 1's verdict row 6: rented hash reorganised Bitcoin Gold, Vertcoin and Musicoin for USD 70 k to 18 M; Igneum's finality bounds this after day 20 and not before, and the first 20 days are when a new chain is watched. The 51 percent paper prices a 12-hour double spend during a pause at USD 146 at 1 GH/s today.
Evidence: 51-percent.md section 5 rank 2; horizon rank 4; past.md section 4 row 6.
Cost: 10 to 16.
Gate: fast-time: a 51 percent fresh-key fork from 15 min back is refused by every honest node; a one-third-weight fork is accepted; partition heal unchanged.
Order: fourth; before the public testnet opens, because the testnet is the first chain outsiders can rent against.
### 2.5 Work-stake (in flight on `work-stake`)
What it is: a vote key may claim an external proving job only if its next window of pool income covers the job's value; a miss, refusal or forgery forfeits that income for one window, the buyer's fee refunded first, the rest to the pool. No balance moves; no coin is posted. The spec sentence lands first: "no coin stake; the only thing at stake is 30 days of public work."
Why it is right: a bond nobody can buy (2,793 IGN at risk for an 8 GB card at 100 GH/s against a 0.0015 IGN coin bond); every attack in its section 6 fails on the window arithmetic.
Evidence: work-stake.md sections 3 to 7; frontier 3.2 and 4.1.
Cost: 24 (orders carried in blocks, the term unwound on reorg, the finality report wired to `judge_at`, the snapshot field, the deadline floor).
Gate: Devnet 2: 1,000 posted jobs with 10 percent injected misses, every injected fault forfeits, zero honest keys forfeit; a 60 s partition across 100 deadlines forfeits nothing.
Order: fifth; it needs the job market of spec 5.4, which the first customer (item 10) needs.
### 2.6 The ladder shown everywhere: the miner's first month (new, lane 5)
What it is: the 30-day vote window as the status ladder on every surface, and the first month's moments built around it. The rungs: first block; 100 blocks and "your key has a vote"; "your signature is in checkpoint K"; 30 of 30 days, full weight; rank by weight; the signing streak; "your card proved shard N of block M". The parts: the Poisson count-up before the first block ("a card like yours finds a block about every 1.6 hours on today's network; chance so far 31 percent"); the block card with a locally drawn PNG and the explorer link; Earnings in IGN first (6,912 IGN a day for a 100 MH/s card at 100 GH/s at the full rate) with a typed price never fetched; the weight leaderboard on `/live` (weight, never hashrate, so a renter sits at the bottom for 30 days); the public address profile behind an opt-in; the hardware census on `/miners` from the hourly program's per-card timings (frontier 4.3); #first-blocks and the Voter and Window roles granted from `getFinalityWeights`.
Why it is the right reinvention: lane 5's archive sample shows the joy posts are the first block, the first payout and the rig photo In a 105-post sample the miner's own posts rise highest: "my card paid for itself" at 777 times the room median against 66 for the network's milestone.; Helium, Chia, Ethereum 2017 and Kaspa 2022 each had a hook, a daily ritual and a status surface, and each status surface was a company number or a hashrate a renter could top. Igneum's is a consensus fact. Nobody has it.
Evidence: reinvent.md sections 1, 2, 3.2 to 3.7, 7; the solo-block expectations per tier at 100 GH/s and 1 TH/s (an 8 GB card: 1.6 h and 16 h; it never reaches the vote line at 1 TH/s, which is why the pool is item 11; the 100-block dust line means an 8 GB card never votes past about 500 GH/s, a question for the finality lane and a watch item, not a list item).
Cost: 35 (Poisson line 2, block card 4.5, earnings 6.5, ladder 6, leaderboard 3, profile 3, census 4, Discord 5, the first-hour timeline on `/miner` 2).
Gate: a Devnet 2 key walks every rung on screen in a view test; every number on the tab names its RPC field on hover; "first share within 10 minutes of download in 9 of 10 fresh Windows installs" published on `/evidence`.
Order: sixth; it is the first thing the first outside miner sees.
### 2.7 Heat mode, the region and price prompt, the cost-against-rent line (new, lanes 3 and 4)
What it is: Ember holds a room temperature or a schedule and the hash follows the duty cycle; a per-region electricity-price prompt with a banned-region line ("mining may be restricted where you are; you are responsible for checking"); the Earnings tab's cost line against the measured rental rate so a miner sees when rented hash undercuts their card.
Why it is right: a 300 W card as a heater breaks even against a UK gas boiler or a COP-3 heat pump at 5.3 p an hour earned and is free against a resistive panel (lane 4 section 5); the heating season credits about a third of a UK or EU miner's bill (lane 3 section 4); lane 3's 2031 row says retail-power tiers leave first when idle datacentre hash sets the rent, and the heat mode keeps winter home miners on. Prior art is Heatbit (2022), 21energy and Qarnot; new only as a chain client's feature, which is the point.
Evidence: invent.md section 5 and rank 2; future.md sections 3, 4 and 10.
Cost: 6 heat mode, 2 region prompt, 2 the rent line. 10.
Gate: a set temperature held within 1 degree for 4 h on PC 1 while hash follows the duty cycle; the prompt shows the right banned list for a Russian region; the rent line reads the bench-log rate.
Order: seventh; app only, no digest, ships in any cut.
### 2.8 Genesis forward-compatibility: the scheme byte, key succession, the cache rung (new, lane 3)
What it is: three genesis fields. A `sig_scheme` byte in the vote item and the key reveal (0 = BLS12-381 today), so a post-quantum scheme flips by the 95 percent signal and not by a fork. The key-succession item (W5, unimplemented on the node) so a key can hand its weight and its forfeit term to a successor once, which is the migration path. A cache-size rung on the signal ladder beside N, because a consumer last-level cache at the cache size (256 MiB) gives that card's owners a 2 to 3x shortcut (chip-model-v3; consumer LLC is 96 to 128 MB today, datacentre 256 MB). The class-group VDF's quantum fallback is flagged, not sized.
Why it is right: naive ML-DSA-44 votes at 8,192 voters cost 19.4 MB a checkpoint and 57 GB a day; with 250x SNARK aggregation about 223 MB a day; a cryptographically relevant quantum computer is "quite possible (28 to 49 percent)" within ten years (Global Risk Institute 2025) and NIST deprecates ECDSA and EdDSA after 2030. The flip is signalled the year of deprecation, not the year a machine appears; the byte costs nothing now and a fork later.
Evidence: future.md section 7 and 10; finality-in-proof.md 7 (W5 absent).
Cost: 10 (the byte and the digest test 4, the W5 item 6, the rung 1 inside the ladder code, the spec text).
Gate: the digest test; a vote item with scheme 1 refused by every node until the signal; a succession carried once and refused twice in the fast-time harness.
Order: eighth; genesis fields must land before item 1's final cut, so this is scheduled with it and listed here for its own gate.
### 2.9 A second proof system on the active list and the one-third stop switch (new, frontier I4 and lane 3)
What it is: a second zkVM behind the `ProofSystem` trait (RISC Zero or OpenVM) proving the same segments on one fleet box as a shadow; a disagreement between the two on any segment is a public alert and the pool stops paying on proofs until 1/3 of weight signals which system to trust. Full nodes keep the native-execution veto whatever happens.
Why it is right: three soundness-class events across SP1 and RISC Zero in 18 months (lane 3 section 5); the veto protects full nodes and nothing protects a light client or the proving pool; lane 3's death row 4 is this.
Evidence: future.md sections 5 and 9; frontier I4; ledger P7 and D6.
Cost: 24.
Gate: 1,000 segments agree across both systems; one injected bad proof disagrees, pays nothing and raises the alert.
Order: ninth; before any phone trusts item 2's object.
### 2.10 The launch pack: gates and text, no protocol (new, lanes 1, 3 and 5)
What it is: lines added to `docs/plans/testnet-go.md` and the litepaper, each with its check. Gates: a signed proving customer before mainnet, with the weight of the Devnet 2 gate; per-tier income published at three prices (USD 0.005, 0.02, 0.10) before the testnet, per the consequences rule; the launch-week hash-origin report (key counts, pool shares, fleet shares) from the observer, daily for the first 90 days; the first 100 keys, the first 1,000 independent keys (the X5 definition), the first pool not run by the project, the first outside-reproduced benchmark, the first block from a card the project does not own; signed and notarised installers (Developer ID, Authenticode) with the measured first-share time per release. Text: the three wants on the front page and finality on page two; "a block pays its miner whether or not anyone buys a proof that day"; the eight regulatory sentences of lane 3 section 8.3 (no issuer, no sale; the sustainability indicators per era; no price language; the pool holds no balance; no privileged key), labelled "not legal advice; counsel is engaged".
Why it is right: lane 1's shape (income halves 60 to 120 days after a peak, under USD 0.10 per kWh within 6 to 18 months, 50 to 100 percent of hash gone in 90 days) and its rows 2, 4, 7 and 9; lane 5's install findings (SmartScreen warns on any file without reputation); lane 3's regulation rows (MiCA 4(3)(b) exempts block-reward assets; the UK regime from 25 October 2027 covers platforms and custody, not mining).
Evidence: past.md sections 3 and 4; future.md section 8; reinvent.md 3.1 and 4.1.
Cost: 15, plus the project lead's certificates and the customer's signature.
Gate: every gate line in testnet-go.md with its check; the forbidden-strings check passes on the new text; the hash-origin report posts on Devnet 2 for seven days before the testnet go.
Order: tenth; text and gates can land any hour, and the customer gate is the one that takes longest.
### 2.11 The pool finished (new, lanes 2, 4 and 5)
What it is: pool-0 run by the project at the testnet go with the member's vote key in every header (the pool holds no weight and no vote), a 1 percent fee published beside the dev fee, PPLNS with a round every 60 s; TLS before the public testnet (spec 9.3) and the pool page rows Q69 to Q73; then the pool without an operator: a P2Pool-style share sidechain in the pool crate, shares forming a 10-second chain committed in the coinbase extra data, the window's payout computed by every node from consensus data as the 20 percent already is, no balance and no operator key, every member running the node the design already assumes. Lane 2's verdict: the finished form is Monero P2Pool's, not SmartPool's (SmartPool's on-chain claims died on gas, and at 1.35 ms per share verification a sampled contract would still need the zkEVM to re-derive a warp unit per sampled share); lane 4's in-protocol pool (shares inside blocks, every node verifying every share) stays refused at 14.6 GB a day per node.
Why it is right: no pool without an operator exists on any chain but Monero (P2Pool at 7.7 percent of hash, 3,520 miners, 0 percent fee; Ocean 2.05 percent of blocks with 85 percent through DATUM; Stratum V2 job declaration at 1 block in 52,297); Igneum already holds the three objects that make one cheap (the vote key in the header, the 20 percent paid by sortition, the coinbase extra data), and nobody has built one on a DAG chain. An 8 GB card at 1 TH/s finds a solo block every 16 hours and 23 percent of its days have none, so the first-month ladder of item 6 depends on a pool from about 1 TH/s.
Evidence: unfinished.md section 5 (5.2, 5.3) and headline 2; invent.md section 4 and rank 13; reinvent.md 3.5 and 1.4; pool.md; spec 09.
Cost: 60 (TLS 8, the pool page rows about 12, the share sidechain about 40).
Gate: 100 members on the fast-time network paid by the coinbase rule from a share chain with no operator key, a withheld share earning nothing, a member's dropped share provable from its own log; the first payout inside two minutes of the first share for an 8 GB card on Devnet 2.
Order: eleventh; pool-0 and TLS before the testnet go, the share sidechain before the network passes about 1 TH/s.
### 2.12 The weight-backed peer directory (new, lane 4, prototype)
What it is: a coinbase section where a key above dust may publish its node's address; a fresh node dials from that list weighted by 30-day weight, beside the DNS seeds.
Why it is right: lane 4's model E bounds an eclipse by a 34 percent attacker at 1.8e-4 with 8 outbound peers and 3.2e-8 with 16; prior art (DNS seeds 2011, discv5 2019, Heilman's eclipse paper 2015) weights nothing by work; lane 3's 2031 death row (weight concentrating in hosting firms) is first seen through such a list.
Evidence: invent.md section 7.1 and rank 4; horizon rank 9 (the peer floor it extends).
Cost: 10.
Gate: a fresh node with genesis peers only reaches 8 outbound from the directory; a 34 percent attacker eclipses under 0.1 percent of 1,000 fresh starts; the NAT fraction measured on the fleet.
Order: last; a prototype, dropped if the NAT fraction makes the list useless.
## 3. Rejected, with the one line that killed each
| Idea | The line |
|---|---|
| A pool inside the protocol (shares in blocks, no operator) | FruitChains (2016): 14.6 GB a day and 5 cores per node at 10,000 miners on a 10 s share; 146 GB and 50 cores at 100,000 |
| A reward slice for serving state or data | a key with no state answers in 108 ms over a 100 ms link; it pays for what the lottery already compels |
| Proof of propagation receipts | no consensus clock; 94 to 376 MB a day of receipts; GHOSTDAG already is a proof of propagation |
| Proof of following beyond class v5 | the epoch seed and the state root already commit to the recent chain |
| A first-block bonus per key | a 10 percent miner collects it 2,592 times a window: an instamine with extra steps |
| Reorg insurance for exchanges, pause insurance from the pool | no slashable payer by ruling; the lock is the product; the pool pays the wrong people |
| Proof of latency, proof of unique card, an energy-price oracle, hash-rate futures in protocol | no clock; nothing counts cards by design; a lever the bid neutralises; needs a coin bond |
| Finality as a service for other chains | kept as a demand-gated prototype only; no customer named, so not on the list |
| The weight-aged reward rule (pay per block falls when hash arrives faster than the weight) | a 30-day income ramp on every honest newcomer, which the first-month ladder cannot afford; revisit only if weight by hosting provider passes a third |
| Mining is proving; useful work in the hash | 2.9 MB of openings per block, a 32 to 40 ms verify against the 10 ms gate; Aleo's fastest-prover-wins |
| Proving others' chains as the main income | all of Ethereum L1's proving is about USD 36 a day against USD 13,700 of year-1 emission |
| Vote-or-burn | 70 to 80 percent respect against the 95 percent test; the signing bonus is on at genesis instead |
| Dormant-coin rent, any holder penalty, a device bounty, a coin stake, Bitcoin anchoring, privacy | refused by ruling |
| A hardware wallet verifying proofs on the secure element | a bn254 pairing on a Cortex-M class element is seconds to minutes; the companion verifies |
| A compute market for unverifiable work | an escrow without a verifier is a trust-me payment with lower fees |
| Merged mining, multi-algo, an auxiliary chain | A child inherits its parent's pool concentration and loses its say in rules; a second hash lane splits the weight table and the DAA (Myriad, Verge, DigiByte); the one merged-mining shape with value is the share sidechain of item 11 |
| Gamification paid from a fund, referral in coins, an airdrop for anything, NFT badges, off-chain points, a rank-by-hashrate board, a top-earners board in fiat, streaks that demote | there is no fund; nothing is for sale; the rung is a chain fact; a renter tops hashrate on day one; the burn was refused |
| Any number that needs a company server to be trusted | every number shown is reproducible from a node, or it is not shown |
## 4. What this round did not run
| Item | Why | Where it sits now |
|---|---|---|
| The H100 and A100 hash rate on rented pods | no pod rented for this round | item 10's measurement line; lane 3 section 3 |
| The in-guest BLS and colouring cycle counts (fin-proof 6.1) | no box slot taken for this document | item 2's cost |
| The 4090 rows for class v5 (section 7 of its page) | the pod window was the class-v5 lane's | item 3's cost |
| Reddit, bitcointalk and the Wayback Machine | refused this environment's fetches; quotes came through search snippets and project forums | past.md section 2, reinvent.md section 1, each labelled |
## 5. The closing line
Nothing is added to this list without removing something. Signed, the mission programme, 7 October 2026.

View file

@ -0,0 +1,304 @@
# The past, honestly: every GPU-mined chain since 2011 and what GPU miners want
Lane 1 of the last mission. Written 7 October 2026 by the past lane for the mission coordinator. Scope: the history of every chain that mattered to GPU miners, what each promised, what each paid, when the GPU miners left, and what the record says Igneum should change. The ASIC side of this history (which hash fell to which chip and how fast) is already in `docs/analysis/asic-resistance-history.md` and is not repeated; this file cites it where a chip is the reason a chain died for GPUs. The emission and governance comparison against Kaspa, Monero, Ethereum and the rollups is in the Horizon economy lane (section 4.6) and is not repeated either.
Every figure from a source carries a URL and the access date in section 6. Every figure from memory is labelled approximate. Reddit, bitcointalk and the Wayback Machine refuse this environment's fetches (sections 2 and 6 say which quotes came through search snippets instead). Times are UK time.
## 0. Progress
| Time (UK, 7 Oct 2026) | State |
|---|---|
| 08:05 | Read CLAUDE.md, asic-resistance-history.md, horizon-2026-10.md section 1, economy-and-utility.md 4.6 |
| 08:10 to 08:45 | 75 web searches and 60 fetches across project blogs, pool blogs, forums, press (search budget exhausted at 08:40) |
| 08:49 | Writing; sections 1 to 6 landed in one pass |
| 08:53 | Length check (258 lines, under the 300 floor); added 1a (the Merge week) and 1b (promised against delivered), split the grouped chain paragraphs, reconciled headline 1's counts against the table |
| 08:58 | Done. File complete, reported to the coordinator |
## 1. One row per chain
Income columns are USD per card per day before electricity unless stated. "Exit" is when the median GPU miner stopped earning more than electricity at USD 0.10 per kWh, or when the lane closed outright. State is October 2026.
| Chain (hash) | Launch | What it promised GPU miners | Peak GPU income (card, date) | Exit income (card, date) | GPU miners left | What killed the GPU lane, or state today |
|---|---|---|---|---|---|---|
| Litecoin (scrypt) | 13 Oct 2011 (approximate) | Memory-hard hash mineable on CPUs and consumer GPUs; no ASIC existed (litecoin.watch) | 200 to 800 kH/s per Radeon, 2012 to 2013; USD per card approximate 1 to 5 | 2014, under power for any GPU once Zeus 28 MH/s at 800 W shipped | Mid 2014 | Scrypt ASIC (Gridseed Jan 2014, Zeus mid 2014, Antminer L3 2017). Today an ASIC chain merged with Dogecoin |
| Dogecoin (scrypt, AuxPoW) | 6 Dec 2013 | A fun scrypt coin for the same GPUs as Litecoin | Approximate USD 1 to 3 per card, Jan to Feb 2014 | Aug 2014 | Aug to Sep 2014 | Merged mining under Litecoin from block 371,337 (28 Aug 2014); hashrate +1,500 percent in a month (Binance Research). GPUs never came back |
| Ethereum (Ethash) | 30 Jul 2015 | GPU-friendly memory-hard hash with a promise to leave for proof of stake | USD 0.233 per MH per day, Jan 2018 (so USD 23 per 100 MH); USD 6.35 to 9.15 per RTX 3080, early 2021 (Minerstat via Wccftech); May 2021 approximate USD 12 to 15 per 3080 | USD 1 to 2 per 3080 on 14 Sep 2022 (approximate) | 15 Sep 2022, all at once | The Merge. About 900 TH/s and about 20 million GPUs (Tom's Hardware estimate) lost 94 percent of GPU income in one block (2Miners: USD 24 M a day to USD 1.2 M) |
| Ethereum Classic (Etchash) | Jul 2016 fork | A home for Ethash GPUs after the Merge | 70.5 to 158 TH/s in 7 hours on 15 Sep 2022 (CoinDesk), 296 to 312 TH/s inside a day | Under electricity for most GPUs within weeks; hashrate -48 percent in four days (AMBCrypto) | Sep to Dec 2022, then again as E9 Pro and Jasminer ASICs took the chain | Today 130 to 186 TH/s, ASIC-dominated; best ASIC nets USD 3.64 a day at USD 0.10 (asicminervalue) |
| Monero (CryptoNight to RandomX) | 18 Apr 2014 | CPU and GPU mining, fork away any ASIC | Vega 56 era 2017 to 2018, approximate USD 2 to 4 per card | 30 Nov 2019: GPU performance "gets a tiny boost or degrades" (MinerUpdate) | 30 Nov 2019: 75 percent of GPU miners offline (MinerUpdate) | RandomX moved it to CPU on purpose; hashrate 300 MH/s to 800 MH/s in weeks. Qubic's rented-CPU campaign claimed 51 percent on 11 Aug 2025 with a 6-block reorg (The Block); the AFT 2026 paper finds no sustained majority and no reward edge |
| Zcash (Equihash 200,9) | 28 Oct 2016 | "Universal accessibility" in mining (forum users' reading of the project) | USD 8 per GTX 1080 Ti, Jul 2017 (WhatToMine via 2Miners) | USD 2.63 per 1080 Ti, 6 May 2018 (2Miners) | Jun to Sep 2018 | Antminer Z9 mini announced 3 May 2018; the company stayed neutral; no fork. ASIC chain since; proof-of-stake migration under discussion (approximate) |
| Ravencoin (X16R, KAWPOW) | 3 Jan 2018 | GPU-only by design; three hash changes to keep it so | Approximate USD 6 to 8 per 3080, Feb to Apr 2021 (RVN peak USD 0.2857) | 3080 loses USD 0.13 to 0.31 a day, 2026 (WhatToMine) | Gradual through 2023 to 2025 | KAWPOW (6 May 2020) cut hashrate 10x as FPGAs left and held off chips for six years; the Merge doubled it (8.9 to 15.9 TH/s). On 7 Aug 2026 a header-validation flaw let blocks carry "no genuine ProgPoW work" and split the chain; RVN -19 percent (crypto.news) |
| Ergo (Autolykos v2) | 1 Jul 2019 (approximate) | Memory-hard, ASIC-resistant, GPU-only (minerstat FAQ) | Approximate USD 3 to 4 per 3080, Sep to Nov 2021 (ERG near USD 15) | USD 0.22 per 3080 before power, Oct 2026 (hashrate.no) | Late 2022 onward | The Merge pushed it from 22 to 155 TH/s in a day (Decrypt); difficulty ate the income within weeks. Still GPU, no chip, income under power |
| Kaspa (kHeavyHash) | 7 Nov 2021 | "GPU PoW", fair launch, no premine (bitcointalk ANN title) | Approximate USD 2 to 3 per 3080, Feb to Mar 2023 | 3070 at USD 1.21 a day, 14 Apr 2023 (2Miners) while a KS2 made USD 361 | Apr to Oct 2023 | IceRiver KS0/KS1/KS2 (Apr to Jul 2023), Bitmain KS3 (May 2023). KS0 earned USD 25 a day in Jul 2023. Today 347 PH/s (hashrate.no), KS7 at USD 1,899, GPUs effectively zero |
| Grin (Cuckaroo29, Cuckatoo31+) | 15 Jan 2019 | 90 percent of blocks for the GPU hash at launch, falling to zero over two years (Grin forum) | Approximate USD 1 to 2 per card, Jan 2019 | 2020 | 2019 to 2020, by schedule | The schedule itself. Today Cuckatoo32 ASIC only, GRIN at USD 0.035, USD 16 k daily volume (minerstat, approximate) |
| Beam (BeamHash III) | 3 Jan 2019 | GPU-friendly Equihash 150,5 | Approximate USD 1 to 2 per card, Jan 2019 | 2020 onward | Most by 2021 | Never an ASIC; the price went. Still GPU-mined, sixth hard fork July 2026, negligible income |
| Conflux (Octopus) | Oct 2020 (approximate) | GPU-only, no FPGA or ASIC | Approximate USD 2 to 3 per 3080, 2021 | USD 0.71 per 3080 before power, Oct 2026 (hashrate.no) | Ongoing | Still GPU at 3.9 TH/s. No chip in six years; income under power for most cards |
| Alephium (Blake3) | Nov 2021 (approximate) | GPU-mineable sharded chain | Approximate USD 1 to 2 per 3080, 2023 | 2024 | May to Oct 2024 | Goldshell AL-Box 360 GH/s at 180 W (May 2024), AL-Box III 1.25 TH/s (Oct 2024). GPUs out in five months; even the ASICs now lose USD 3.44 a day at USD 0.10 (asicminervalue) |
| Nexa (NexaPow) | 21 Jun 2022 | CPU first, then GPU, "scale to global capacity" | Top of the GPU tables Jul 2023 (2Miners) | 2024 (approximate) | 2024 (approximate) | Price. Approximate: down over 99 percent from its 2023 high; hashrate a fraction of 2023 |
| Aleo (PoSW) | 18 Sep 2024 | Proving as mining on GPUs | USD 13.50 per RTX 4090 at ALEO USD 9, Sep 2024 (PANews via AiCoin) | Under USD 5 per 4090 at USD 3.40, late 2024 (same source) | Q4 2024 to 2025 | Price and allocation: a one-year lock on early rewards, validators seeded with 270 k to 1.1 M tokens, 10 M stake to validate; f2pool holds 28.9 percent of proving (hashrate.no). "Difficulty plummeted ... as miners exited" |
| Iron Fish (Blake3, FishHash) | 20 Apr 2023 | GPU mining of a private chain | Approximate USD 1 to 2 per 3080, Apr 2023 | USD 0.48 per 3080 before power, Oct 2026 (hashrate.no) | 2023 to 2024 | Blocks of "unknown origin and hash power" within weeks (FPGA suspected); FishHash fork 2 Apr 2024 kept it GPU; the price did the rest |
| Flux (ZelHash) | 2018 as Zel | GPU-only Equihash 125,4 | USD 50 k a day across the chain, Sep 2022 (2Miners) | Late 2025 | Late 2025 | Proof of Useful Work v2 (RunOnFlux, 23 Oct 2025): FluxNodes produce all blocks; "GPUs stopped having any relevance to FLUX rewards" |
| Firo (MTP, FiroPoW) | 2016 as Zcoin | GPU-only ProgPoW variant since 26 Oct 2021 | 4x hashrate after the Merge | USD 0.56 per 3080 before power, Oct 2026 (hashrate.no) | Ongoing | No chip in five years. Still GPU, 13 to 54 GH/s, small |
| Vertcoin (Lyra2RE, Verthash) | 8 Jan 2014 | "The people's coin", fork away every ASIC | Approximate USD 1 to 2 per card, Dec 2017 | 2019 | 2018 to 2019 | Two rental 51 percent attacks (Dec 2018: 300-block reorg, about USD 100 k; 1 Dec 2019: 603 blocks replaced, NiceHash). Verthash (Jan 2021) kept GPUs; nobody came back |
| Bitcoin Gold (Equihash-BTG) | Oct 2017 | "Make Bitcoin decentralized again" on GPUs | USD 474 a coin, Dec 2017 | 2018 | 2018 to 2020 | 51 percent attacks: May 2018 (388,000 BTG, up to USD 18 M), Jan 2020 (29 blocks, USD 70 k). Delisted by Binance 1 Sep 2024 and Upbit 23 Jan 2025; "under 100 actively reachable nodes" (Decrypt) |
| EthereumPoW (Ethash) | 16 Sep 2022 | Ethereum mining continues | Above USD 140 a coin at launch | 2022 to 2023; profitability -85 percent from peak | Within months | Price: USD 1.70 by mid 2025 (99 percent down); pools left for ETC |
| Nervos CKB (Eaglesong) | 16 Nov 2019 | GPU-mineable launch | 300 GTX 1070 Ti earned USD 410 a day, 19 Nov 2019 (2Miners) | The same rig earned USD 4.46 a day, 21 Mar 2020 | Mar 2020 | Hashrate 198 TH/s to 1.99 PH/s in 16 days before any chip was sold (secret ASICs); Antminer K5 Apr 2020 at USD 22 then 11 a day |
| Radiant (SHA512/256d) | 2022 (approximate) | "GPU/ASIC mining" in the ANN title | Approximate USD 1 per 3080, 2023 | Sep 2024 | Sep 2024 | IceRiver RX0 and DragonBall A11 ASICs, Sep 2024. Designed to go to ASIC |
| Karlsen, Pyrin, Nomura (kHeavyHash forks) | Nov to Dec 2023 | "We will ensure long-term GPU-friendly mining" (Karlsen README) | Approximate USD 0.5 to 1 per 3080, Dec 2023 | 2024 | 2024 | Karlsen moved to FishHash (KarlsenHashv2, 12 Sep 2024) as kHeavyHash chips arrived; Pyrin was called "another pre-mine scam" on bitcointalk (five days of private mining before the announced start) |
| Dynex (DynexSolve) | Sep 2022 | Proof of useful work, "the most GPU mined coin" (22 percent of Hive OS, Oct 2023) | Approximate USD 2 to 4 per 3080, mid 2023 | 2024 | 2024 | Price: 99.9 percent below its USD 1.39 high (CoinGecko). The useful-work marketplace never paid the miners |
| Qubic (uPoW) | 2022 (approximate) | AI training as mining, CPU first | By 2025 about 90 percent of its compute was GPU rigs (Qubic blog) | n/a | Rotating | Pivoted to CPU incentives, then rented its idle fleet to Monero (May to Aug 2025, 27,000 blocks, USD 3.5 M), then to Dogecoin ASIC mining (1 Apr 2026). A hashrate broker, not a GPU chain |
| Clore (Kawpow) | 2022 | GPU coin paid for GPU rental | ATH USD 0.45, 17 Mar 2024 | Dec 2025 | Dec 2025 | Proof of work "ended" at block 1,584,180 (Clore changelog, Dec 2025): "miner sell pressure fully removed". A 4090 rents for USD 1.18 to 2.45 a day there |
| TurtleCoin (CryptoNight Turtle) | Dec 2017 | A friendly CPU/GPU coin | Negligible | Mar 2023 | 15 Mar 2023 | Halted at block 5,500,000; token moved to Fantom (TurtleCoin v2 FAQ). Dead as a chain |
| Musicoin (Ethash) | 2017 | Ethash side income | Negligible | 2019 | Jul 2019 | Repeated 51 percent attacks, Bittrex delisting, 2Miners delisting (31 Jul 2019: "Musicoin is dead") |
| Akroma (Ethash) | 2018 | Ethash side income with masternodes | Negligible | 2019 | Jul 2019 | Developers left; USD 92 daily volume; delisted by 2Miners |
| Callisto (Ethash) | 2018 | Ethereum Classic airdrop chain | Negligible | 2024 | 2024 | Team liquidity crisis and "civil war" in 2024 (Callisto history page). Dead |
### 1a. The Merge week, the one migration with hour-level data
| When (UK) | What happened | Source |
|---|---|---|
| 15 Sep 2022, 07:43 | The Merge; Ethereum's last proof-of-work block; about 900 TH/s of GPU hash loses its income | Tom's Hardware |
| 15 Sep 2022, 07:00 to 14:00 | ETC from 70.5 to 158.3 TH/s; RVN from 8.9 to 15.9 TH/s; ERG from 22 to about 70 TH/s | CoinDesk, Decrypt |
| 15 to 16 Sep 2022 | ETC peaks at 296 to 312 TH/s (about a third of Ethereum's hash); ERG peaks at 155 TH/s (7x) | AMBCrypto, crypto.news, Decrypt |
| 16 Sep 2022 | ETHW mainnet; the fork trades above USD 140 and falls for three years | KuCoin price history |
| 19 Sep 2022 | ETC hashrate down 48 percent from its peak in four days | AMBCrypto |
| Sep 2022 | Hiveon pool: 16 percent of its miners to ETC, 7 percent to RVN, the rest spread or gone | Hiveon |
| 12 Sep 2022 (before) | 2Miners' arithmetic: USD 24 M a day of GPU income, 94 percent of it Ethereum; USD 1.2 M a day left for all GPU coins after | 2Miners, The Block |
The arithmetic is the whole story: the receiving chains had one twentieth of the income and received, for a day, one third of the hash. Difficulty did the rest. The 2Miners advice of the day was to pick ETC, RVN or ERG "at least for the first days", and the first days were all there were.
### 1b. Promised against delivered
| Chain | The launch text (quoted or paraphrased) | What GPU miners got | Months of GPU income |
|---|---|---|---|
| Grin | 90 percent of blocks to the GPU hash at launch, falling to zero over two years (forum, Aug 2018) | Exactly that | About 18 |
| Ravencoin | GPU-only, fork away FPGAs (KAWPOW, May 2020) | GPU-only for six years; a header bug, not a chip, split the chain in 2026 | 100 and counting, under power since about 2023 |
| Kaspa | "GPU PoW", fair launch (bitcointalk ANN title) | 17 months, then chips at 20x and more per joule | 17 |
| Karlsen | "We will ensure long-term GPU-friendly mining" (README) | A second hash in nine months to keep the promise; income under power either way | 10 |
| Iron Fish | A GPU-mined private chain | Unknown hardware inside weeks; a GPU hash a year later | 12, then under power |
| Aleo | Proving as mining on GPUs | USD 13.50 a day per 4090 for a few weeks, then price and pools | 3 |
| Flux | GPU-only, "resistance to concentrated specialized-hardware advantages" | Seven years, then block production moved to nodes | 84, then closed |
| Clore | Mine the coin that pays for GPU rental | Proof of work ended in December 2025; rental stayed | 36 |
| Nervos | GPU-mineable launch | 16 days of 10x hashrate growth from secret chips four months in | 4 |
What the table says, chain by chain, in one short paragraph each.
**Litecoin.** The first GPU coin and the first proof that a memory-hard hash on paper is a compute-bound hash in a fab. Scrypt with a 128 kB scratchpad fit on a chip in 27 months. GPU miners did not vote or fork; they sold the cards. Lesson for Igneum: the dataset has to be bigger than any die the chip can afford, and the lane's own history (asic-resistance-history.md rows Scrypt) already prices this.
**Dogecoin.** The only chain on the list whose GPU exit was a decision, not a defeat. Merged mining handed security to Litecoin's ASICs and the hashrate rose 15x in a month. Lesson: a small chain that shares hardware with a big one is mined by the big one's miners whenever the big one's miners choose; Igneum's hash has no big sibling, which is a feature and a cost.
**Ethereum.** Seven years of GPU income, three cycles, one exit that was announced for five years and still removed 94 percent of all GPU mining income in one block. The money went to ETC, RVN and ERG for days and then to the shelf. Lesson: miners follow income, not loyalty, and an exit that is scheduled is still an exit.
**Ethereum Classic.** The refugee chain. It absorbed a quarter of Ethereum's hashrate within hours and lost half of that within four days, then went to ASICs. Lesson: a chain that receives a migration gets a difficulty shock, not a community.
**Monero.** Four hash forks in 20 months kept chips off and cost 85 percent of hashrate each time (asic-resistance-history.md). RandomX then chose CPUs on purpose and three quarters of the GPU miners left in a day. In 2025 a rented CPU fleet (Qubic) claimed a majority and produced a 6-block reorg; the peer-reviewed analysis finds no sustained majority and no profit. Lesson: ASIC resistance by hand is a treadmill; a majority that cannot profit still frightens exchanges.
**Zcash.** The clearest record of a project refusing to fork for its GPU miners. The forum poll ran in February 2018, the Z9 shipped in May, the company stayed neutral, the GPUs left by autumn. Income per 1080 Ti fell from USD 8 to USD 2.63 before the chip arrived, because the price fell first. Lesson: the price kills before the chip does.
**Ravencoin.** The one chain that forked three times and kept the GPUs for six years. KAWPOW cut hashrate 10x on fork day because the FPGAs left. Then in August 2026 a validation bug (not a chip) split the chain. Lesson: random-program hashes work; the client is the next weak point, and Igneum has one client.
**Ergo.** A GPU-only hash that never saw a chip and still pays USD 0.22 a day per 3080. The Merge gave it 7x the hashrate in a day and the difficulty took the income back in weeks. Lesson: the hash is not the income.
**Kaspa.** The template Igneum forked. A fair launch, a compute-bound hash, 17 months of GPU income, then IceRiver and Bitmain in the same quarter. In April 2023 a 3070 made USD 1.21 a day beside a KS2 making USD 361. The GPU share went to nothing by the end of the year while the chain prospered. Lesson: the chain can win while its GPU miners lose; Igneum's whole bet is that these two must not separate.
**Grin and Beam.** Both launched in January 2019 into a bear market. Grin scheduled its own GPU lane to die over two years and it did. Beam never had a chip and still lost its miners to the price. Lesson: a launch into a falling market with a thin order book does not get a second chance; the ramp must survive a bad first year.
**Conflux, Firo, Iron Fish.** Three GPU-only hashes with no chip after five to six years, each paying under a dollar a day per card. Lesson: resisting the chip buys the right to be small.
**Alephium.** A sharded chain with a plain Blake3 hash, GPU-mined for about 30 months, then Goldshell shipped a 180 W box in May 2024 and a 1.25 TH/s box five months later. The GPUs were out by autumn and by 2026 the boxes themselves lose money at USD 0.10. Lesson: a chip on a small chain eats the GPUs and then eats itself; the chain gets neither back.
**Nervos.** The extreme case of private hardware. Hashrate rose 10x in 16 days in March 2020, four months after launch and a month before the first ASIC was on sale; a 300-card GPU farm went from USD 410 a day to USD 4.46. Lesson: the first ASIC is always private, and the launch ramp has to assume one.
**Radiant.** Said "GPU/ASIC" in its own announcement title and went to ASIC on schedule in September 2024. Lesson: a chain that invites the chip gets the chip; honest, and not Igneum's path.
**EthereumPoW.** The fork that promised Ethereum mining would continue. The coin traded above USD 140 for a day and under USD 2 by 2025; the pools left for Ethereum Classic within months. Lesson: a fork keeps the code and loses the market; the market is what paid the miners.
**Karlsen, Pyrin, Nomura.** Three kHeavyHash forks launched into the gap the Kaspa chips opened. Karlsen kept its README promise by changing its hash within a year; Pyrin was called a premine scam on launch day; Nomura is a title. Lesson: "the GPU version of X" is a business model with a nine-month half-life.
**Nexa.** Fair launch, CPU first, the top of the profitability tables for a summer, then price. Lesson: being the most profitable coin on WhatToMine for a month is a sell signal, not a community.
**Aleo.** The one chain where mining was proving. The fastest provers took the reward, the pools took the rest, the price fell from USD 9 to USD 3.40 and the GPUs left; the record also shows what miners say when insiders hold the supply. Lesson: Igneum's separation of lottery and proving is the right answer to the first half; the allocation half is answered by having no allocation.
**Flux, Clore, Dynex, Qubic.** Four projects that stopped paying GPUs for hashing and told miners to rent, host or train instead. Flux moved block production to nodes, Clore ended proof of work and pays for rental, Dynex's marketplace never paid, Qubic became a hashrate broker for Monero and then Dogecoin. Lesson: "useful work" projects abandon the miner the day the useful work does not pay; Igneum's proving must be priced to clear (Horizon rank 7) or it is Dynex.
**Vertcoin, Bitcoin Gold, Musicoin.** The three small chains 51 percent attacked by rented hash, between USD 70 k and USD 18 M a time. Each was GPU-only and each was attacked because it was. Lesson: a GPU chain is rentable by definition; finality has to be something hash cannot buy.
**EthereumPoW, TurtleCoin, Akroma, Callisto.** Dead by price, by halt, by abandonment, by a team's money running out. Lesson: a chain with no market is a chain with no miners within a year.
## 2. What GPU miners say they want
Twenty posts and articles read in full or in snippet, 2018 to 2026. Each quote is under 15 words. Reddit threads could not be fetched from this environment, so the miner voice here comes from project forums, pool blogs, bitcointalk snippets and press that quoted miners by name.
| # | Date | Forum or source | Quote | URL |
|---|---|---|---|---|
| 1 | 25 Feb 2018 | Zcash forum, user vgm | "Centralized ASIC mining will destroy hobby mining along with any organic user growth potential." | forum.zcashcommunity.com/t/lets-talk-about-asic-mining/27353 |
| 2 | 25 Feb 2018 | Zcash forum, user JKDC | "Decentralization is as important as privacy." | same thread |
| 3 | 26 Feb 2018 | Zcash forum, user aoeu | "I'd rather have GPUs for general computation, not silicon trash." | same thread |
| 4 | 25 Feb 2018 | Zcash forum, user Autotunafish | "Zcash is about universal accessibility, not a select few" | same thread |
| 5 | 27 Aug 2018 | Grin forum, igno.peverell (launch text) | "A healthy and grassroot GPU mining community at launch is highly desirable." | forum.grin.mw/t/proof-of-work-update/713 |
| 6 | 30 Nov 2019 | MinerUpdate (RandomX day) | "Honest miners will be fighting an uphill battle against botnets" | minerupdate.com (section 6) |
| 7 | 21 Mar 2020 | 2Miners blog (Nervos) | "ASICs or FPGA's are to blame for a sudden increase in the hash rate." | 2miners.com/blog/nervos-ckb-network-hashrate-increased-asics-are-the-cause/ |
| 8 | 9 Apr 2020 | VoskCoinTalk, user Rocky_Bro | "Those 3000watt beasts just eat slower devices for breakfast." | voskcointalk.com/t/.../172 |
| 9 | 12 Sep 2022 | The Block, Ethan Vera (Luxor) | "You have to have sub $0.03 per kilowatt hour and new generation GPUs." | theblock.co (section 6) |
| 10 | 12 Sep 2022 | The Block, Mark D'Aria (Bitpro) | "Ethereum is 95% of the total income. Everything else will get crushed." | same article |
| 11 | 12 Sep 2022 | 2Miners blog, Confessions of a Miner 2 | "When mining makes you lose the money you stop mining." | 2miners.com/blog/confessions-of-a-miner-2-is-this-the-end-of-gpu-mining/ |
| 12 | Sep 2022 | Hiveon pool, year review | "16% moving to ETC, 7% going to RVN" | hiveon.com/news/reflection-and-forecast-... |
| 13 | 2023 (approximate) | bitcointalk, "Kaspa asics" thread (snippet) | "Specialized mining equipment optimized for corporate industry raping" | bitcointalk.org/index.php?topic=5449022.0 |
| 14 | Dec 2023 | bitcointalk, Pyrin ANN thread (snippet) | "another pre-mine scam" | bitcointalk.org/index.php?topic=5476198.0 |
| 15 | 2023 | bitcointalk thread title | "Why most premined coins (>90% of all altcoins) will eventually fail" | bitcointalk.org/index.php?topic=5457833.0 |
| 16 | 14 May 2024 | Iron Fish blog (on its own launch) | "unknown origin and hash power" | ironfish.network/learn/blog/2024-05-14-fish-hash-audit |
| 17 | 2024 | Karlsen README (launch text) | "We will ensure long-term GPU-friendly mining." | github.com/karlsen-network/karlsend |
| 18 | Sep 2024 | PANews via AiCoin, Aleo community user | "When you don't know where the liquidity comes from, you are the liquidity." | aicoin.com/en/article/419859 |
| 19 | 31 Jul 2019 | 2Miners blog (delisting) | "Musicoin is dead, Akroma is irrelevant." | 2miners.com/blog/akroma-and-musicoin-delisting/ |
| 20 | 10 Feb 2026 | Clore blog | "losing money mining with most mid-range GPUs at average electricity rates" | blog.clore.ai/gpu-mining-is-dead-... |
### The three wants, with counts
| Want | Posts asking for it (of 20) | Evidence rows |
|---|---|---|
| 1. Hardware that stays useful: no chip, no FPGA, a card that games or computes when the coin dies | 10 | 1, 2, 3, 4, 5, 7, 8, 13, 16, 17 |
| 2. Income above electricity that does not fall off a cliff | 6 | 9, 10, 11, 12, 19, 20 |
| 3. A fair supply: no premine, no insider allocation, a coin somebody will buy | 4 | 14, 15, 18, 19 |
### The three hates, with counts
| Hate | Posts (of 20) | Evidence rows |
|---|---|---|
| A. Secret hardware on the chain before anyone can buy it | 5 | 7, 8, 13, 16, and Nervos (section 1) |
| B. Premine, VC allocation, locked airdrops | 3 | 14, 15, 18 |
| C. The income cliff and the dead market (an exit, a delisting, a 99 percent drawdown) | 5 | 10, 11, 12, 19, 20 |
### Mapped to Igneum's design (horizon-2026-10.md section 1 and the litepaper)
| Want or hate | Status | Mechanism, and the honest gap |
|---|---|---|
| Want 1, hardware stays useful | Partly answered | Random-program hash with hourly swaps, 256 MB dataset with 8 dependent reads, era draws from chain state, no scheduled fork (CLAUDE.md design paragraph). The chip model says 2.1x per joule at class v4 and the N ladder is a decision owed (Horizon item 4 and rank 10). Kaspa's chip was 20x to 1,200x; 2.1x is a different world, but a 2.1x chip at scale still ends home mining on power price alone. The gap is the ladder decision and a public chip model per era |
| Want 2, income without a cliff | Partly answered | 100 IGN a block gliding 2.9 percent a month, no halving day, a 1 percent tail (tail-emission.md). No chain on this list ever had a cliff-free schedule, so this is new. The gap: every exit in section 1 came from price, not schedule, and no protocol sets price. What Igneum can do is publish the per-tier income at three prices before launch (the consequences rule) so nobody buys a card on a number that was never promised |
| Want 3, fair supply | Answered | No premine, no dev fund, no fee to any team, 90-day ramp from 10 percent (CLAUDE.md, tail-emission.md). Aleo and Pyrin are the counter-examples and Igneum has nothing they had |
| Hate A, secret hardware at launch | Partly answered | The ramp from 10 percent makes the first 90 days worth less to a private farm; the correlated-group detector and `security_alert` (Horizon rank 16) show it; the hourly program swap means a private FPGA bitstream has to be re-made every hour. Not answered: a private rented GPU fleet is not hardware and is allowed; Nervos's 16-day 10x rise would look the same on Igneum's charts. The gap is a published launch-week hash-origin report (pools, key counts, fleet shares) so the community sees it the day it happens |
| Hate B, premine and allocations | Answered | As Want 3 |
| Hate C, the cliff and the dead market | Not answered by protocol | The glide removes the schedule cliff and the proving market gives the coin a buyer other than an exchange (Horizon 4.1a), but a rollup customer paying in dollars is a contract not yet signed (Taiko is the first named customer). Until a customer pays, Igneum has the same exposure as Ergo in 2023: a good hash, a thin market |
One more thing the posts do not say and the record does: nobody on these forums asked for finality, for a DAG, or for proving. They asked for a card that keeps its value, a bill that gets paid, and a coin that sells. Igneum's technical answers are to questions miners did not ask; the mission should put the three wants on the front page and the finality on page two.
## 3. The earnings curve as a pattern
USD per card per day before electricity. A 3080 draws about 220 W, so electricity at USD 0.10 per kWh is USD 0.53 a day; a 4090 at 400 W is USD 0.96. Where a figure is approximate it says so.
| Chain | Launch | Peak month | Peak income (per 100 MH Ethash or per 3080 equivalent) | Month income fell under power at USD 0.10 | Hashrate that left in the next 90 days |
|---|---|---|---|---|---|
| Ethereum | Jul 2015 | Jan 2018, then May 2021 | USD 23 per 100 MH (Jan 2018, USD 0.233 per MH); approximate USD 12 to 15 per 3080 in May 2021 | Never for a 3080 before the Merge (approximate USD 1 to 2 a day in Sep 2022, over power); the lane closed 15 Sep 2022 | 100 percent of Ethereum's 900 TH/s; of the GPUs, about a quarter tried ETC and half of those left inside four days (CoinDesk, AMBCrypto); approximate 80 percent of the cards were off within 90 days |
| Kaspa | Nov 2021 | Feb to Mar 2023 (approximate) | Approximate USD 2 to 3 per 3080 | Approximate Sep to Oct 2023 (a 3070 was at USD 1.21 in Apr 2023 as the first ASICs landed) | GPU share from near 100 percent to under 10 percent by Dec 2023 (approximate); the network's total hashrate rose the whole time |
| Ergo | Jul 2019 | Sep to Nov 2021 | Approximate USD 3 to 4 per 3080 | Approximate Nov to Dec 2022 (the Merge took hashrate from 22 to 155 TH/s in a day) | Approximate 50 to 70 percent of the post-Merge peak within 90 days |
| Ravencoin | Jan 2018 | Feb to Apr 2021 | Approximate USD 6 to 8 per 3080 | Approximate Nov 2022 (the FTX month); a 3080 now loses USD 0.13 to 0.31 a day | Approximate 40 percent of the post-Merge peak (15.9 TH/s) within 90 days |
| Aleo | Sep 2024 | Sep 2024 | USD 13.50 per 4090 at USD 9 (PANews) | Approximate Q1 2025 as the price reached USD 3.40 and difficulty followed the pools | "Difficulty plummeted ... as miners exited" (PANews); approximate over 50 percent of GPU provers within 90 days of the token-economics reveal |
What the curve means per tier (the consequences rule), using the record's ratios rather than a price nobody can promise:
| Tier | What the record says happens to them | What Igneum should tell them before launch |
|---|---|---|
| Home miner, one 8 or 12 GB card | First under power in every exit (the 3060 lost money on Clore's 2026 table while the 4090 still cleared) | Income per card at three prices, and that the glide never halves it overnight; the card keeps gaming when the income goes |
| Home miner, one 16 to 32 GB card | Last GPU standing; still under power 6 to 18 months after a peak on every chain in the table | The proving pool is the second income for this tier only; say so, with the measured 15.6 GB profile |
| Rig (6 to 12 cards) | Followed income across chains inside days (Hiveon: 16 percent to ETC, 7 percent to RVN) and shut down inside 90 days | Rig income at three prices; no loyalty expected, none needed, the 30-day weight pays staying miners a vote |
| Pool user | Took the pool's choice of chain and the pool's fee; pools held 29 percent of Aleo proving at launch | Which pools carry the finality signer, and that a pool's vote is the user's weight (ledger G8) |
The common shape, in numbers: income peaks inside one to six months of a price run or a migration, halves within 60 to 120 days as difficulty catches the price, and falls under power within six to eighteen months of the peak; when it does, 50 to 100 percent of the GPU hashrate leaves inside 90 days. The trigger was a chip twice (Kaspa, and ETC's second decline), a scheduled exit once (Ethereum), and the price three times (Ergo, Ravencoin, Aleo). In no case did a GPU lane recover its peak income after the exit.
## 4. Verdict table
| # | Lesson | Evidence (chain, year) | What Igneum does today | Gap | What the mission should add or change |
|---|---|---|---|---|---|
| 1 | A compute-bound hash goes to a chip in 16 to 37 months, and the first chip is private | Litecoin 2014, Zcash 2018, Nervos 2020, Kaspa 2023, Alephium 2024 | Random-program hash, 256 MB dataset, latency shadow, era draws; chip model 2.1x at class v4 (Horizon item 4) | Small | Decide the N ladder at genesis and publish the chip model with every era draw; nothing else |
| 2 | Secret hardware or fleets show up as an unexplained hashrate step in the first weeks | Nervos 2020 (10x in 16 days), Iron Fish 2023, Kaspa 2023 | 90-day ramp from 10 percent; correlated-group detector and `security_alert` (Horizon rank 16) | Small | A public launch-week hash-origin report (key counts, pool shares, fleet shares) from the observer, daily for the first 90 days |
| 3 | Hash forks by hand lose miners and add bugs; the client is the next failure | Monero 2018 to 2019 (85 percent gone per fork), Vertcoin 2018 to 2019, Ravencoin Aug 2026 (header flaw) | No scheduled human fork; era draws from chain state; 95 percent signalling with a floor; Devnet 2 gate | Large on the client | The second independent client is the item; until then a fuzz gate on header and PoW validation paths equal to the sync-request fuzz (Horizon rank 9) |
| 4 | Income cliffs empty a chain in days; miners follow income with no loyalty | Ethereum Sep 2022 (94 percent of income gone), ETC -48 percent in four days, Aleo Q4 2024 | Monthly glide, no halving day, 1 percent tail (tail-emission.md) | Small on schedule, large on price | Publish per-tier income at three prices (USD 0.005, 0.02, 0.10) in the litepaper before the testnet, per the consequences rule; nothing in protocol |
| 5 | Premine and insider allocation drive GPU miners out faster than any chip | Aleo 2024, Pyrin 2023 | No premine, no dev fund, no fee to any team | None | Nothing |
| 6 | A GPU chain is rentable; rented hash reorganised three of them for USD 70 k to USD 18 M | Bitcoin Gold 2018 and 2020, Vertcoin 2018 and 2019, Musicoin 2019 | Miner-only finality on 30 days of blocks; 20 days of 100 percent hash to reach 2/3 (CLAUDE.md) | Small after day 20, large before | Weight-gated deep fork choice (Horizon rank 4) covers the first 20 days; ship it before mainnet, not after |
| 7 | A coin with no market dies within a year whatever the hash does | Musicoin 2019, Akroma 2019, TurtleCoin 2023, Grin (USD 16 k daily volume), Nexa | Proving sold in dollars, settled in IGN (litepaper); Taiko named as first customer | Large until a customer pays | A signed proving customer before mainnet is a launch gate, with the same weight as the Devnet 2 gate; decouple the job price from `f_p` (Horizon rank 7) so the first job can clear |
| 8 | Useful-work projects drop the miner the day the work does not pay | Dynex 2024, Flux 2025, Clore 2025, Qubic 2025 to 2026 | The lottery pays 80 percent of every block whatever the proving market does; proving is the second income, never the only one | None by design | Write the sentence into the litepaper: "A block pays its miner whether or not anyone buys a proof that day" |
| 9 | Random-program hashes keep GPUs for five years and more, and still pay under a dollar a card | Ravencoin 2020 to 2026, Firo, Conflux, Iron Fish | The hash is Igneum's strongest answer | None on the hash | Stop presenting the hash as the reason to mine; present income, fairness and the second income (section 2's three wants) first |
## 5. Headline findings for the coordinator
1. Of the 31 rows (33 chains) that paid GPU miners since 2011, 8 lost the GPU lane to a chip, 7 closed it by their own choice (Dogecoin, Ethereum, Monero, Grin, Flux, Clore, Qubic), 10 died or went dormant on price, rental attacks or abandonment, and the 6 still GPU-only (Ravencoin, Ergo, Firo, Conflux, Iron Fish, Beam) pay USD 0.22 to 0.71 a day per RTX 3080 before power, so the hash keeps the miner and not the income.
2. In 20 miner posts and launch texts read, 10 asked for hardware that keeps its value, 6 for income above electricity without a cliff and 4 for a fair supply; Igneum answers the fair supply in full, the hardware in part (a 2.1x chip model with the N ladder still owed), and the income only on schedule, since every GPU exit in the record except two came from price.
3. The earnings curve has one shape across Ethereum, Kaspa, Ergo, Ravencoin and Aleo: income halves within 60 to 120 days of the peak, falls under USD 0.10 per kWh within 6 to 18 months, and 50 to 100 percent of GPU hashrate leaves inside 90 days of that, so the launch plan needs a signed proving customer and published per-tier income at three prices before the first miner buys a card.
## 6. Sources (all accessed 7 October 2026 unless noted)
Project and pool sources
- Zcash forum, "Let's talk about ASIC mining", Feb 2018: https://forum.zcashcommunity.com/t/lets-talk-about-asic-mining/27353
- Grin forum, "Proof of work update", 27 Aug 2018: https://forum.grin.mw/t/proof-of-work-update/713
- 2Miners, Nervos hashrate and ASICs, 21 Mar 2020: https://2miners.com/blog/nervos-ckb-network-hashrate-increased-asics-are-the-cause/
- 2Miners, Akroma and Musicoin delisting, 31 Jul 2019: https://2miners.com/blog/akroma-and-musicoin-delisting/
- 2Miners, End of Ethereum mining, 30 Aug 2022: https://2miners.com/blog/end-of-the-ethereum-mining-when-what-to-mine-next-with-gpu-transition-to-pos-explained/
- 2Miners, Confessions of a Miner 2, 12 Sep 2022: https://2miners.com/blog/confessions-of-a-miner-2-is-this-the-end-of-gpu-mining/
- 2Miners, How to mine Kaspa with ASIC and GPU, 14 Apr 2023: https://2miners.com/blog/how-to-mine-kaspa-with-asic-and-gpu-settings-extra-rewards-dual-mining/
- 2Miners, July 2023 report (Nexa, Kaspa KS0 port): https://2miners.com/blog/july-2023-work-progress-report-new-coin-nexa-kaspa-geo-servers/
- 2Miners, KawPoW fork, May 2020: https://2miners.com/blog/kawpow-new-ravencoin-mining-algorithm/
- Hiveon, PoW to PoS notes, 24 Aug 2022: https://hiveon.com/news/the-pow-and-pos-transition-important-notes/
- Hiveon, 2022 review (16 percent ETC, 7 percent RVN): https://hiveon.com/news/reflection-and-forecast-reviewing-the-events-of-2022-and-anticipating-the-year-ahead/
- VoskCoinTalk, Antminer K5 impressions, 9 Apr 2020: https://voskcointalk.com/t/initial-impressions-of-the-bitmain-antminer-k5-nervos-ckb-eaglesong-asic-miner-mining-22-a-day/172
- Iron Fish, FishHash audit and the reason for the switch, 14 May 2024: https://ironfish.network/learn/blog/2024-05-14-fish-hash-audit
- Iron Fish, hard fork 1 activation, 2 Apr 2024: https://ironfish.network/learn/blog/2024-02-26-mainnet-hardfork
- Karlsen README: https://github.com/karlsen-network/karlsend
- hashrate.no, Karlsen and Pyrin algorithm change, 13 Sep 2024: https://www.hashrate.no/c/Algorithm_change_for_Karlsen_and_Pyrin
- hashrate.no, RTX 3080 today (top coins and USD per day): https://hashrate.no/gpus/3080
- hashrate.no, Kaspa network (347 PH/s): https://www.hashrate.no/coins/KAS
- hashrate.no, Aleo pools (f2pool 28.9 percent): https://www.hashrate.no/coins/ALEO/pools
- RunOnFlux, Proof of Useful Work v2, 23 Oct 2025: https://runonflux.com/forking-flux-proof-of-useful-work-v2/
- Clore changelog (PoW end, Dec 2025): https://clore.ai/changelog
- Clore blog, GPU mining is dead, 10 Feb 2026: https://blog.clore.ai/gpu-mining-is-dead-gpu-hosting-is-the-future-heres-how-to-earn-500month/
- Qubic blog, mining evolution, 30 Jun 2025: https://qubic.org/blog-detail/qubic-mining-evolution-from-cpu-roots-to-gpu-dominance-and-back-again
- Qubic blog, Dogecoin mining on Qubic: https://qubic.org/blog-detail/qubic-dogecoin-mining-how-it-works
- TurtleCoin v2 FAQ (halt at block 5,500,000, 15 Mar 2023): https://hackmd.io/@iburnmycd/rJzyWD3-_
- Callisto history (2024 collapse): https://www.callisto-pirl.com/history
- bitcointalk, Kaspa ANN: https://bitcointalk.org/index.php?topic=5373286.0 (403 on fetch; title and snippet via search)
- bitcointalk, "Kaspa asics": https://bitcointalk.org/index.php?topic=5449022.0 (snippet only)
- bitcointalk, Pyrin ANN: https://bitcointalk.org/index.php?topic=5476198.0 (snippet only)
- bitcointalk, Karlsen ANN: https://bitcointalk.org/index.php?topic=5475216.0 (snippet only)
- bitcointalk, "Why most premined coins will eventually fail": https://bitcointalk.org/index.php?topic=5457833.0 (title only)
- asicminervalue, Antminer KS7: https://www.asicminervalue.com/miners/bitmain/antminer-ks7-40th
- asicminervalue, Goldshell E-AL1M (negative at USD 0.10): https://www.asicminervalue.com/miners/goldshell/e-al1m
- asicminervalue, Ethereum Classic: https://www.asicminervalue.com/coins/etc-ethereum-classic
- minerstat, Grin: https://minerstat.com/coin/grin_cuckatoo32
- WhatToMine, Ravencoin on RTX 3080 LHR: https://whattomine.com/coins/234-rvn-kawpow/gpus/63-nvidia-geforce-rtx-3080-lhr
- Binance Research, merged mining case study: https://www.binance.com/en/research/analysis/merged-mining
- litecoin.watch, scrypt history: https://litecoin.watch/articles/understanding-the-scrypt-mining-algorithm
Press and papers
- CoinDesk, ETC and RVN hashrate after the Merge, 15 Sep 2022: https://www.coindesk.com/tech/2022/09/15/ethereum-classic-and-ravencoins-hashrate-nearly-doubles-after-merge
- AMBCrypto, ETC post-Merge high wearing off, 19 Sep 2022: https://ambcrypto.com/why-ethereum-classics-etc-post-merge-high-is-wearing-off/
- crypto.news, ETC hashrate +280 percent: https://crypto.news/ethereum-classic-hashrate-jumped-280-post-merge/
- Decrypt, ETC, RVN and ERG hashrate soar, Sep 2022: https://decrypt.co/109803/ethereum-classic-ravencoin-ergo-hash-rate-soar-post-merge
- The Block, what is left for GPU miners, 12 Sep 2022: https://www.theblock.co/news/ecosystems/2022-09-12-whats-left-for-ethereum-gpu-miners-after-the-merge-168380
- Tom's Hardware, GPU mining unprofitable after the Merge (900 TH/s, about 20 million GPUs): https://www.tomshardware.com/news/gpu-mining-is-now-unprofitable
- Wccftech (Minerstat figures, RTX 3080 USD 6.35 to 9.15 a day, early 2021): https://wccftech.com/rgb-lit-bitcoin-mining-rig-78-geforce-rtx-3080-graphics-cards-comes-operational/
- FXStreet, Ethereum miners in the red (USD 0.233 per MH per day in Jan 2018), 29 Mar 2018: https://www.fxstreet.com/amp/cryptocurrencies/news/ethereum-price-analysis-eth-usd-eyes-40000-amid-cryptocurrency-sell-off-miners-are-deep-in-red-201803290719
- MinerUpdate, CPU mining dominates Monero since RandomX, 30 Nov 2019: https://www.minerupdate.com/news/miner-insights/cpu-mining-dominates-monero-since-randomx-upgrade
- Bitcoin Magazine, Antminer Z9 mini, May 2018: https://bitcoinmagazine.com/business/bitmains-antminer-z9-mini-designed-mine-zcash-threatens-asic-resistance
- 2Miners, Zcash mining and profitability (1080 Ti at USD 8 in Jul 2017, USD 2.63 on 6 May 2018): https://2miners.com/blog/how-to-mine-zcash-zec-mining-and-profitability/
- Medium (Blockwise), the end of GPU mining (Monero April 2018 fork halved hashrate): https://medium.com/blockwise/the-end-of-gpu-mining-a702921fc1e1
- crypto.news, Ravencoin consensus flaw, 11 Aug 2026: https://crypto.news/ravencoin-falls-as-consensus-flaw-splits-network/
- Decrypt, the long collapse of Bitcoin Gold: https://decrypt.co/47381/the-long-collapse-of-bitcoin-gold
- metalicjames gist, Bitcoin Gold Jan 2020 attack: https://gist.github.com/metalicjames/71321570a105940529e709651d0a9765
- metalicjames gist, Vertcoin Dec 2018 attack: https://gist.github.com/metalicjames/f2acdb9ef448ec5298173b36c7c54133
- news.bitcoin.com, Vertcoin second attack, Dec 2019: https://news.bitcoin.com/vertcoin-network-sabotaged-by-another-51-attack/
- Binance Square, BTG delisting 1 Sep 2024: https://www.binance.com/en/square/post/12128321695753
- AiCoin (PANews), Aleo mainnet, miners cry foul, Sep 2024: https://www.aicoin.com/en/article/419859
- Aleo, mainnet announcement, 18 Sep 2024: https://aleo.org/post/announcing-aleo-mainnet/
- The Block, Monero reorg fears after Qubic's 51 percent claim, 12 Aug 2025: https://www.theblock.co/post/366535/monero-faces-chain-reorganization-fears-after-qubic-says-it-controls-51-of-hashrate
- Lee and Kim, Inside Qubic's selfish mining campaign on Monero, arXiv 2512.01437, AFT 2026: https://arxiv.org/abs/2512.01437
- Decrypt, Qubic mining Dogecoin, Apr 2026: https://decrypt.co/363018/qubic-the-network-that-captured-51-of-monero-is-now-mining-dogecoin-on-its-ai-compute-infrastructure-live
- CoinGecko, Dynex (99.9 percent below ATH): https://www.coingecko.com/en/coins/dynex
- Medium (crypto-blog), Dynex the most GPU mined coin, Oct 2023: https://medium.com/crypto-blog/dynex-dnx-seems-to-be-the-most-gpu-mined-coin-at-the-moment-cdf7d30c433a
- KuCoin, ETHW price history: https://www.kucoin.com/price/ETHW
- Kryptex, IceRiver KS series: https://pool.kryptex.com/articles/iceriver-ks0-ks1-ks2-ks3-ks3l-en
- Medium (VoskCoin), Was Kaspa mining worth it (KS0 USD 25 a day, Jul 2023): https://medium.com/voskcoin/was-kaspa-mining-worth-it-ca3ac9ff7566 (403 on fetch; figures via search snippet)
Internal
- `docs/analysis/asic-resistance-history.md` (5 Oct 2026)
- `docs/analysis/horizon-2026-10.md` section 1 and ranks 4, 7, 9, 10, 16 (6 to 7 Oct 2026)
- `docs/analysis/horizon/economy-and-utility.md` section 4.6
- `docs/analysis/tail-emission.md`, `docs/analysis/vote-or-burn.md`
Not reachable from this environment (recorded so the coordinator can fetch by hand): reddit.com (all subreddits), bitcointalk.org thread bodies, web.archive.org, the Springer paper "The PoW Landscape in the Aftermath of The Merge" (login wall), statista's Ethereum profitability series (paywall), bitinfocharts chart values (rendered client-side).

View file

@ -0,0 +1,446 @@
# Mission lane 5: what can be reinvented. The miner's experience
Date: 7 October 2026, UK time. Lane 5 of the last mission. Written in the mission worktree; this file is the only output. Nothing was built, measured, posted or started; the live devnet was not touched.
the project lead's words that this lane holds: "revolutionise the mining itself"; "dopamine for GPU miners everywhere, a structure that makes the mining commodity fall in love with the project"; "the perfect gpu network that will be noticed as the revolution that everyone is waiting for". Bounds that this lane obeys: no premine, no dev fund, no treasury, no token sale, no airdrop, no referral paid in coins; every coin is mined under the rules that exist (the 80/20 split, the signing bonus of 8 of the 80 producer points, the proving pool); no stake; no device bounty; the three signalling thresholds (60, 90, 95); miners are the security always; gates, not dates; hours are agent hours.
## 0. Progress
| Time (UK) | State |
|---|---|
| 08:46 | Rules read: CLAUDE.md, polish.md sections 1, 3.1, 3.2, 3.4, 3.6, 3.7, 3.10, 4.5; litepaper miner sections; vote-or-burn section 5; tail-emission one page; horizon one page; ledger decisions 3, standing, 6 and 7 October; pool.md; miner-ui-3 and its audit; testnet-go; the dev fee; the Discord kit; the Reddit kit (branch reddit-kit); journey.json |
| 09:05 | Three research sub-lanes launched: Reddit post sample, chain histories, pool and install facts. The third refused by the concurrency limit; its topics done by hand with WebFetch. The session's WebSearch budget was already spent by other lanes, so every outside fact below comes from a fetched page or is labelled approximate |
| 08:52 | Igneum maths computed (scratch `mission-reinvent/igneum-maths.txt`, `tiers.txt`): solo block expectations per tier at 100 GH/s and 1 TH/s, the vote dust line, the signing bonus per day |
| 09:04 | Sections 3 to 8 drafted; 1.1 and 2 waiting on the sub-lanes |
| 09:10 | Section 1.1 and headline 3 written from `reddit-sample.md` (105 posts, 69 with a room median) |
| 09:13 | Section 2 and the sources written from `chains.md` (seven chains, hashrates derived from explorer APIs at dated heights) |
| 09:15 | Done: 0 em dashes by grep, no placeholders, 446 lines; the three findings sent to the coordinator |
## 1. The dopamine loop of a GPU miner, from data
### 1.1 What the archives say
Method (the sub-lane's file, scratch `mission-reinvent/reddit-sample.md`): 105 posts picked by hand from the top-of-all-time listings of r/EtherMining, r/gpumining, r/chia, r/ravencoin, r/MoneroMining, r/Monero, r/HeliumNetwork (2021 to 2022), r/kaspa and r/erg_miners (r/ErgoMining is an empty shell whose top post points to r/erg_miners), plus six bitcointalk "first block" posts from 2011 to 2017 through the ninjastic archive. Each post's score is the value Reddit served on 7 October 2026. The subreddit median for the post's year is estimated from three half-month samples of the Arctic Shift archive (approximate; the typical post in these rooms scores 1 to 4 points, so the ratios are large and describe how far the best joy posts rise above an ordinary post). 69 of the 105 rows have a ratio; r/MoneroMining and r/erg_miners have no archive sample.
| Post type | Rows with a ratio | Median score | Median ratio to the room's typical post | Range | Best example (score, date, URL) |
|---|---|---|---|---|---|
| f. "My card paid for itself" (ROI, break-even) | 6 | 777 | 777x | 493x to 1,367x | solar panels paid for by mining, 1,367 points, 16 May 2021, https://www.reddit.com/r/gpumining/comments/ndduuu/ |
| g. The community meme | 11 | 710 | 739x | 81x to 2,054x | "New miners be like...", 2,054 points, 19 Apr 2021, https://www.reddit.com/r/EtherMining/comments/mu3jgh/ |
| c. The rig photo | 13 | 361 | 417x | 48x to 2,923x | "Rate my new build", 2,923 points, 3 Mar 2021, https://www.reddit.com/r/EtherMining/comments/lwpudz/ |
| d. The hashrate milestone | 7 | 324 | 409x | 95x to 672x | "What 1GH looks like", 672 points, 8 Apr 2021, https://www.reddit.com/r/EtherMining/comments/mmybn2/ |
| e. The profit screenshot, "X per day" | 7 | 234 | 234x | 48x to 593x | "I finally mined a full Ethereum today", 593 points, 21 Jul 2021, https://www.reddit.com/r/EtherMining/comments/ootl28/ |
| a. First block found solo | 8 (plus 6 bitcointalk rows with no score) | 233 | 119x | 46x to 762x | "Tried Solo Mining ETH as an Experiment, Ended up Hitting a Block", 762 points, 3 Jun 2021, https://www.reddit.com/r/EtherMining/comments/nr13be/ |
| h. "We did it", the network milestone (ATH, listing, hotspot count, halving) | 12 | 214 | 66x | 12x to 305x | Helium's first telecom deal, 305 points, 26 Oct 2021, https://www.reddit.com/r/HeliumNetwork/comments/qg9o6g/ |
| b. First payout | 5 | 173 | 56x | 43x to 478x | "I made my first bitcoin penny", 478 points, 8 Mar 2021, https://www.reddit.com/r/gpumining/comments/m0emml/ |
| all | 69 | 256 | 297x | 12x to 2,923x | |
What the ranking says. The posts that rise highest are about the miner, not the network: the card that paid for itself (777x), the rig in a photo (417x), the personal hashrate milestone (409x). The network's own milestone, the thing a project would post, sits near the bottom (66x). The first solo block is the strongest single feeling in the quotes and a middling score (119x), because it is rare; the first payout is the lowest (56x), because on a pool it is routine. Chia's first-block posts are the exception that proves it: on a chain where the first win took weeks of plotting, "It finally happened! I never thought this day would come" scored 615 (19 May 2021, https://www.reddit.com/r/chia/comments/ngevxy/), 308x its room's median. The Monero room shows the same feeling at every size of CPU: "After 271 days and 101 Billion Hashes, I Finally Mined my First Monero" (128 points, 20 Nov 2020, https://www.reddit.com/r/MoneroMining/comments/jxxwzo/).
Quotes (verbatim, with the sub-lane's dates and URLs; all accessed 7 October 2026):
| Quote | Where | Date |
|---|---|---|
| "GUYZ! I DID IT! I FINALLY WON!!" | r/chia title, https://www.reddit.com/r/chia/comments/myaizh/ | 25 Apr 2021 |
| "cries in 17TiB with 0 xch" | top comment on the same post | 25 Apr 2021 |
| "380 MH/s, about 24 hours total time mining. Very, very lucky." | r/ravencoin, https://www.reddit.com/r/ravencoin/comments/pnfl4y/ | 13 Sep 2021 |
| "That's crazy. Now all of us pool miners are going to think hmm." | r/EtherMining, https://www.reddit.com/r/EtherMining/comments/nr13be/ | 3 Jun 2021 |
| "1 GH/s and disappointed parents achieved!" | r/gpumining title, https://www.reddit.com/r/gpumining/comments/okexp4/ | 14 Jul 2021 |
| "Love solo mining its the best." | r/MoneroMining, https://www.reddit.com/r/MoneroMining/comments/1uexakh/ | 25 Jun 2026 |
| "I just solo mined my first block ever! :3 Feels good." | bitcointalk, https://bitcointalk.org/index.php?topic=619210.msg6866375#msg6866375 | 22 May 2014 |
| "Mind blown." | bitcointalk, first reply to "just found my first block", https://bitcointalk.org/index.php?topic=338903.0 | 19 Nov 2013 |
Consequence for Igneum, by surface: the shareable thing must be the miner's own object (the block card with the card's name on it, the rig's row on the census, the weight rank), never the project's milestone; the ROI post cannot exist without a price, so its stand-in at the testnet is the line "N IGN per kWh" and the days-mined ring; and the solo first block must stay reachable for the common tier, which is the reason the Poisson line and the pool switch sit on the same screen (section 3.2).
### 1.2 Time to the first hit on each chain
| Chain, year | First hit | Measured or estimated time from install | Source |
|---|---|---|---|
| Ethereum 2017, pool (Ethermine, Nanopool) | first share accepted, worker on the dashboard | share within seconds of the first job; worker visible in 1 to 10 minutes; first payout at 0.05 ETH took one GTX 1070 about 2 to 3 weeks in mid 2017 (approximate) | approximate, from memory of the pool pages |
| Ethereum 2017, solo | first block | a 30 MH/s card against 60 TH/s: one block in about 2 million blocks, 1 year or more; nobody did it (approximate) | approximate |
| Kaspa, launch day 8 Nov 2021, solo | first block | the network was 3.4 MH/s on 8 Nov 2021 (derived from the header bits, `chains.md`), so one 2021 card found blocks within minutes; at 2.86 TH/s six months later the same card needed a pool | https://api.kaspa.org/blocks-from-bluescore?blueScore=100000 (7 Oct 2026) |
| Kaspa 2022, pool (2miners) | first share; payout at 50 KAS every 2 hours | share in seconds; payout the same day for a 1 GH/s card in 2022 (approximate); 2miners: "Payouts are processed automatically every 2 hours", minimum 50 KAS | https://2miners.com/faq and https://kas.2miners.com/ (7 Oct 2026) |
| Monero 2019, p2pool (from 2021) | a share in the PPLNS window, paid at the next pool block | p2pool: "It can take several days to a week to find a share if your hashrate is low"; min payout 0.00027 XMR | https://p2pool.io/ (7 Oct 2026) |
| Chia 2021 | the first plot finished (the hit was the plot, not the coin) | 6 to 12 hours a plot on a consumer SSD; the expected solo win on 10 TB at 5 EiB netspace was months (approximate) | r/chia posts of May 2021 (section 1.1); approximate |
| Helium 2021 | the hotspot on the map, the first beacon, "HNT per day" in the app | hours after power-on, days to weeks of waiting for the device itself (the r/HeliumNetwork top post of 2021 is a photo of a miner six months after ordering, section 1.1) | section 1.1 |
| Ravencoin 2018, solo | first block, 5,000 RVN | on launch day any card found blocks in minutes (approximate) | approximate |
| Igneum devnet, 2026 | first accepted block, shown in the app's event feed | an Apple silicon laptop through the DMG: first block "within the first minutes", 33 accepted blocks in 7 minutes; an RTX 5090 through the Windows installer: 34 accepted blocks in the first minute once the clock was right | `docs/bench-log.md` 4 October 2026 (the first outside machine; the three-card rig) |
### 1.3 The loop
| Stage | What it is for a miner | Evidence |
|---|---|---|
| Trigger | a number moved: a block, a payout, a hashrate tick, a chart on the explorer, a post in the feed | the post types that score highest are all "a number moved and here is the screenshot" (section 1.1) |
| Action | open the app, the pool page, the explorer, the Discord; refresh | the daily ritual on every chain in section 2 |
| Variable reward | blocks are a Poisson draw; the payout varies; the post's upvotes vary; luck is the word every pool shows | 2miners shows "luck 441%" and "last block 2 minutes ago" on the pool's front page (https://kas.2miners.com/, 7 Oct 2026) |
| Investment | a rig built, plots made, a key aged, a reputation in the room, a name on a board | Chia's plots, Helium's named hotspot on the map, the EtherMining rig-photo post (section 1.1) |
Igneum has one investment no other chain has: the vote key's 30-day window. A key that mined for 30 days weighs more than the same hashrate that appeared yesterday, and that weight signs finality. That is a level system written into consensus, and section 3.7 builds the ladder on it.
### 1.4 The five moments on Igneum, and the time to each today
Computed at 1 block a second, the producer share of 80 points, 100 IGN a block at full rate. The network size is the variable: the first 1,000 miners at the measured median card (about 25 MH/s, section 3.8) are about 25 GH/s; 100 GH/s is the litepaper's example; 1 TH/s is where the loop breaks for solo cards. Full tables per tier: section 3.8 and scratch `tiers.txt`.
| Moment | Solo, 100 MH/s on 100 GH/s | Solo, 17 MH/s (8 GB) on 100 GH/s | Pool member, any card | Where it is shown today | Where it should be shown |
|---|---|---|---|---|---|
| 1. First share or first block | first block: expected gap 16.7 min, 97 percent within the first hour | 1.6 h expected, 46 percent within the first hour | first share: vardiff starts at one share per 10 s and the first correction is sized from the measured rate (`pool.md` section 2), so under a minute after the first job; before that the node sync and the dataset build (measured: the devnet laptop's first block "within the first minutes") | the event feed and the blocks strip (`app.js:1052-1127`) | the block card of section 3.3 |
| 2. First payout | the coinbase of the first block, credited by the execution layer when the block is blue; so the payout is the block, seconds later | the same | PPLNS credit on blue confirmation; a payout round every 60 s (`pool/src/config.rs:61`), minimum 1 IGN; an 8 GB member at 100 GH/s earns 1 IGN in about 73 s, so the first payout lands inside two minutes of the first share | Earnings reads "£0.00 earned" and never shows mined IGN (Q18) | Earnings as section 3.4 |
| 3. First proof shard paid | shards are assigned by lot to eight provers for ten seconds; 388 shards and 446.13 IGN paid on 5 October (the Discord kit's start-here text); on a 24 GB NVIDIA card today, 12 GB cards with the patched prover measured not shipped | not available on 8 GB today (core-only proving measured, `prover-tiers-real-cards.md` rows 4060) | proving income never passes through the pool (C6) | Prove tab state line "0 proven · 0 paid" | "your card proved shard N of block M" as a card, section 3.7 |
| 4. First vote (the key above dust, 100 blocks in the 30-day window) | 1.2 days | 6.8 days | the member's own blocks carry its key (`pool.md` section 2, Votes), so the same days as solo for the same card; a member without a node has no vote (spec 09 9.7) | nothing: the app never says whether the key votes | "your key has a vote" card, the ladder rung 1 |
| 5. First signature in a certified checkpoint, then the full window | the first checkpoint after the key enters the table (one checkpoint is 30 s; a young key counts as present); the full window at day 30 | the same; full window at day 30 | the same | nothing | "your signature is in checkpoint K" and "30 of 30 days" |
The consequence of the dust line, per tier (the standing rule of 5 October): at 100 GH/s every tier reaches a vote inside a week; at 1 TH/s a single 8 GB card finds 44 blocks in 30 days and never reaches 100, so it never votes, and the pool does not help because weight follows the member's own found blocks. The 12 GB RTX 4070 reaches 65, also under. The RTX 5090 reaches 255. So past about 500 GH/s the "your key has a vote" rung is out of reach for the cards most of the first 1,000 miners own, and the X5 gate (1,000 independent keys above dust) gets harder as the network grows. This lane does not touch the constant; it hands the finality lane the question in section 8 and keeps the ladder's first rungs (first block, first payout, first shard, 30 days mined) reachable for every tier at any network size.
## 2. The product structures that made miners fall in love
Method (the sub-lane's file, scratch `mission-reinvent/chains.md`): hashrates derived from block difficulty at dated heights through each chain's public explorer API (Ergo, Monero, Ravencoin, Kaspa) or Etherscan's daily CSV (Ethereum); Helium and Chia from their own HIPs, blog posts and release notes; prices from CoinGecko. Every URL opened on 7 October 2026. "Approximate" marks a figure from memory. Hash units differ across forks and are not compared across them.
### 2.1 The hook, the ritual, the proof, the ladder, the story
| Chain | Hook | Daily ritual | Social-proof surface | Status ladder | The story a miner told |
|---|---|---|---|---|---|
| Helium 2019 to 2021 | a USD 500 box on the windowsill mines by giving radio coverage | the app or explorer.helium.com: the hotspot's 24-hour HNT, witnesses, "relayed" | the explorer hex map; every hotspot a dot with a three-word name; "the map was the product" | none formal: "first in my city" on the map, maker badges in Discord, validators from 2021 (approximate) | HIP 10's own example: a hotspot "which has earned approximately $21,000 worth of HNT by purchasing $145 worth of DC" (https://github.com/helium/HIP/blob/main/0010-usage-based-data-transfer-rewards.md) |
| Chia 2021 | farm on drives you already own; "green Bitcoin" from the BitTorrent inventor | the GUI's netspace and "estimated time to win"; plots finishing; then the pool page | the netspace chart (chiaexplorer, xchscan); the pool leaderboard | plot count and TiB; "OG plots" against portable plots (approximate beyond that) | "It finally happened! I never thought this day would come" (section 1.1); the other side: "cries in 17TiB with 0 xch" |
| Ethereum 2017 | the gaming PC prints money while you sleep | WhatToMine with your card list, the pool's unpaid balance and graph, the overclock | the pool's worker list and "estimated earnings"; YouTube rig builds; the GPU price chart | rig size (6, 8, 12 cards), hashrate, the "paid off" post (approximate) | "In Feb this subreddit told me it was too late and I'd never ROI" (893 points, 1 Aug 2021, https://www.reddit.com/r/EtherMining/comments/ovvaah/) |
| Kaspa 2022 | "No premine. No hidden allocation. Fair launch." (https://kaspa.org/) | miningpoolstats.stream, the pool dashboard, Discord #mining | the miningpoolstats hashrate chart and pool count | Discord roles for early miners and pool operators (not verified, approximate) | "I mined six figures of KAS on two GPUs at a tenth of a cent" (approximate, the room's tone) |
| Monero RandomX 2019 | any CPU, even a laptop, mines again; RandomX "optimized for CPUs" (https://www.getmonero.org/resources/moneropedia/randomx.html) | the xmrig console, the pool page, the electricity maths | the RandomX README benchmark table (i9-9900K 5,770 H/s, Ryzen 7 1700 4,100, i3-3220 510, Raspberry Pi 3 20; https://github.com/tevador/RandomX) and the pool's miner count | none formal; hashes per watt bragging | "After 271 days and 101 Billion Hashes, I Finally Mined my First Monero" (section 1.1) |
| Ravencoin 2018 | Bitcoin's fair launch replayed for GPUs; "no private, public, founder, or developer allocation" (https://ravencoin.org/assets/documents/Ravencoin.pdf) | the pool dashboard, the WhatToMine line, Discord #mining, "is that hashrate jump an FPGA?" | the pool ranking and the explorer difficulty chart | none formal | "380 MH/s, about 24 hours total time mining. Very, very lucky." (section 1.1) |
| Ergo 2019 | the ETH miners' second home: GPU-only Autolykos, a 2 GB table, "hardcoded no-premine proof" (https://github.com/ergoplatform/ergo/releases/tag/v3.0.0) | the pool dashboard, the explorer, WhatToMine, Discord #mining | the hashrate chart and the pool list | none formal | "My first payout. All mined with my humble GTX 1060 at 50MH/s." (section 1.1) |
What the seven have in common: the daily ritual is a number read off a page the project does not control (a pool, miningpoolstats, WhatToMine); the social proof is a chart or a map; the ladder is informal everywhere. Helium is the one chain whose product was the proof surface itself (the map), and it is the one whose miners posted photos of the device six months after ordering (section 1.1). No chain had a ladder the chain itself computed.
### 2.2 The numbers at 3, 6 and 12 months
| Chain, launch | 3 months | 6 months | 12 months | Peak | Source |
|---|---|---|---|---|---|
| Helium, 1 Aug 2019 | about 1,500 hotspots (approximate) | about 3,000 (approximate) | about 7,500 (approximate) | "500,000+ Hotspots" (HIP 54, 2 Feb 2022); "close to 1 million" (HIP 70, 30 Aug 2022) | https://raw.githubusercontent.com/helium/HIP/main/0054-h3dex-targeting.md ; https://github.com/helium/HIP/blob/main/0070-scaling-helium.md |
| Chia, 19 Mar 2021 (transactions 3 May) | "over 30 exabytes" (7 Jul 2021) from "about 100 pebibytes" at launch | 32 EiB (3 Aug 2021) | 28 EiB (19 Mar 2022); "over 400,000 nodes" | about 35 to 40 EiB late 2021 (approximate); 17.3 EiB on 7 Oct 2026 | https://www.chia.net/2021/07/07/official-pooling-protocol-launched/ ; https://www.chia.net/2022/03/19/chia-mainnet-year-one/ ; https://alltheblocks.net/chia |
| Ethereum GPU, from 1 Jan 2017 (6.0 TH/s) | 17.3 TH/s (1 Apr 2017) | 37.2 TH/s (1 Jun 2017) | 159.4 TH/s (1 Jan 2018) | 1,126.7 TH/s (13 May 2022); 871.0 TH/s on 14 Sep 2022, zero from 16 Sep | https://etherscan.io/chart/hashrate?output=csv |
| Kaspa, 7 Nov 2021 (3.4 MH/s on 8 Nov) | about 1 TH/s (approximate; 0.3 TH/s on 19 Dec 2021) | 2.86 TH/s (28 May 2022) | 431.8 TH/s (26 Nov 2022) | 210.7 PH/s (12 Apr 2024, derived); about 344 PH/s on 7 Oct 2026 | https://api.kaspa.org/blocks-from-bluescore?blueScore=15800001&includeTransactions=false ; https://api.kaspa.org/info/hashrate?stringOnly=false |
| Monero RandomX, 30 Nov 2019 (307 MH/s CryptoNightR before, 686 MH/s RandomX on 1 Dec) | 1,338 MH/s (29 Feb 2020) | 1,372 MH/s (30 May 2020) | 1,695 MH/s (29 Nov 2020) | 7.54 GH/s (16 Jan 2026) | https://xmr-node.cakewallet.com:18081/json_rpc (get_block_header_by_height) ; https://www.coinwarz.com/mining/monero/hashrate-chart |
| Ravencoin, 3 Jan 2018 | 0.89 TH/s (19 Mar 2018) | 1.31 TH/s (17 Jun 2018) | 3.51 TH/s (7 Jan 2019) | X16R 22.5 TH/s (29 Sep 2019); KAWPOW 18.76 TH/s (20 Sep 2022); 0.61 TH/s on 7 Oct 2026 | https://blockbook.ravencoin.org/api/v2/block/130000 (and later heights) ; https://rvn.2miners.com/api/stats |
| Ergo, 1 Jul 2019 | 1.06 TH/s (1 Oct 2019) | 1.29 TH/s (31 Dec 2019) | 7.89 TH/s (30 Jun 2020) | 180.6 TH/s (17 Sep 2022); 0.47 TH/s on 7 Oct 2026 | https://api.ergoplatform.com/api/v1/blocks?limit=1&offset=66000&sortBy=height&sortDirection=asc (and other offsets) ; https://erg.2miners.com/api/stats |
Discord member counts were not found in any source opened for any of the seven; the one community-size number in the sample is r/erg_miners passing 5,000 subscribers on 6 Jan 2022 (section 1.1, row 104).
What the first year looked like from a card: Kaspa went from 3.4 MH/s on its first day to 2.86 TH/s at six months, a million-fold, and then 150x more in the next six (the post-Merge fleet); Chia's netspace rose about 300x in under four months, so a fixed farm's share fell 300x; Ethereum rose 26x across 2017. A miner who joined on day one of any of them watched their share fall by two or three orders of magnitude inside a year. Igneum's 30-day window gives that miner something the hashrate curve took away: weight that the newcomers cannot buy for 30 days.
### 2.3 The failure modes
| Chain | What broke | The number | Source |
|---|---|---|---|
| Helium, 2022 | dilution then gaming then a pivot: emission halved to 2,500,000 HNT a month (1 Aug 2021, HIP 20) while hotspots went past "close to 1 million", so under 0.1 HNT a day per hotspot against about 5 to 10 in 2020 (approximate); a denylist run by the company from about 14 Jan 2022 whose method is not published; subDAO tokens with a "50B pre-mine" of MOBILE (HIP 53); the move to Solana (April 2023); the SEC complaint of 17 Jan 2025 over claims about Lime, Nestlé and Salesforce, settled for USD 200,000 | HNT ATH USD 54.88 to ATL 0.1132; "almost 38% of all HNT is staked in Validators" (HIP 70) | https://raw.githubusercontent.com/helium/HIP/main/0020-hnt-max-supply.md ; https://github.com/helium/denylist ; https://raw.githubusercontent.com/helium/HIP/main/0053-mobile-dao.md ; https://www.sec.gov/enforcement-litigation/litigation-releases/lr-26229 ; https://www.coingecko.com/en/coins/helium |
| Chia, 2021 | the SSD burn (about 1.3 TiB of writes per plot, Chia's own figure; consumer drives killed in weeks, the press figure approximate), the pool protocol eight months after the pools promise (11 Nov 2020 to 8 Jul 2021) with "OG plots" shut out of it, a closed pool at a third of netspace, 300x dilution in four months, then consolidation and a price fall of 99.9 percent | hpool "hovering at around 33% of netspace" (15 Jun 2021); XCH ATH USD 1,645.12 to ATL 1.14 | https://www.chia.net/2021/05/24/chia-and-ssd-endurance/ ; https://www.chia.net/2021/06/15/common-misconceptions-vol-1/ ; https://github.com/Chia-Network/chia-blockchain/releases/tag/1.2.0 ; https://www.coingecko.com/en/coins/chia |
| Ethereum, 15 Sep 2022 | the Merge switched 871 TH/s off in a day; ETC absorbed at most 236.6 TH/s; Ergo rose 11x in 48 hours (16.1 to 180.6 TH/s) and Ravencoin 7x (2.70 to 18.76 TH/s), so every existing Ergo rig lost about 91 percent of its share inside a week; both fell back by Christmas (32.6 and 9.19 TH/s) | the bagpipes post: "Powering down last ETH mining rig the only proper way", 2,277 points, 15 Sep 2022, https://reddit.com/r/EtherMining/comments/xek7wq | https://etherscan.io/chart/hashrate?output=csv ; https://bitinfocharts.com/comparison/hashrate-eth-etc.html ; https://decrypt.co/109713/ethereum-classic-hashrate-soars-merge-nears-miners |
| Kaspa, 2023 | the ASIC turn: IceRiver KS0 to KS3 listed for "Sep 2023", Bitmain KS3 "Oct 2023"; network hashrate 2.67 PH/s (28 Jul 2023) to 115.7 PH/s (19 Dec 2023), 43x in under five months; one KS1 at 1 TH/s equals about 2,000 RTX 3070-class cards (approximate), so the GPU share went to a rounding error | 43x | https://www.asicminervalue.com/miners/iceriver ; https://api.kaspa.org/blocks-from-bluescore (derived) |
| Monero, 2019 onward | nothing broke on chain; two slow failures: botnet mining ("Monero's popularity among malware-based non-consensual miners", Wikipedia), and a 4x hashrate rise to the 2026 peak against the 0.6 XMR tail | 686 MH/s (1 Dec 2019) to 7.54 GH/s (16 Jan 2026) | https://en.wikipedia.org/wiki/Monero ; https://www.coinwarz.com/mining/monero/hashrate-chart |
| Ravencoin, 2019 to 2020, then 2022 | the FPGA and ASIC surge: 10.0 to 22.5 TH/s between 22 Aug and 29 Sep 2019 with no price move; two algorithm forks (X16Rv2, 1 Oct 2019, "ASIC shmasic"; KAWPOW, May 2020, hashrate 29.4 to 3.39 TH/s overnight); then the economic break after the Merge, 18.76 TH/s to 0.61 TH/s today, and a "consensus flaw in KAWPOW header validation" rescued by a pool in Aug 2026 | hashrate down 97 percent from the 2022 peak; RVN down 99.2 percent | https://github.com/RavenProject/Ravencoin/releases?page=2 ; https://github.com/RavenProject/Ravencoin/releases/tag/v4.1.0 ; https://2miners.com/blog/august-2026-work-progress-ravencoin-chain-rescue-pearl-hard-fork-and-kaspa-reward-cut/ |
| Ergo, 2022 | the overflow pipe: 16.1 TH/s (3 Sep 2022) to 180.6 (17 Sep), back to 36.8 by 3 Oct; 0.47 TH/s today, under 3 percent of the peak | 11x up and 80 percent down in a month | https://api.ergoplatform.com/api/v1/blocks (derived) ; https://erg.2miners.com/api/stats |
What Igneum takes from each: from Helium, a proof surface the miner owns (the map) and a warning that a company-run denylist with an unpublished method ends the love (section 6, "a number a company server has to be trusted for"); from Chia, that the ritual (plotting) must not destroy the hardware, and that a pool that arrives eight months late with the early miners shut out is remembered (pool-0 is at the go, section 3.5); from Ethereum, that the shareable post is the rig and the ROI, and that a chain can end mining by decree (Igneum's miners are the security always, so there is no Merge to decree); from Kaspa, that a fair launch holds a community for two years and an ASIC takes it in five months (the hourly program and the census, 4.4); from Monero, that "anyone's CPU" is a narrative that survives seven years when the hash keeps its promise; from Ravencoin, that two algorithm forks by human release are what Igneum's automatic schedule replaces; from Ergo, that a hashrate wave arriving from a dead chain dilutes the faithful 11x in two days, which is exactly what the 30-day weight window was built to keep from the vote.
## 3. The miner's experience on Igneum, reinvented
### 3.1 Install: the two warnings before the first screen
What happens today (polish.md 3.10): Windows, SmartScreen "Windows protected your PC" (More info, Run anyway), per-user install, then a UAC prompt for the firewall rule 20 to 50 s in, on top of whatever screen is up. Mac, an ad hoc signature, Gatekeeper refuses, the user must find Privacy and Security, Open Anyway; the app strips its own quarantine on start. The Windows installer cannot be rebuilt tonight (Q80, GitHub billing).
What the comparators do: SmartScreen warns on any file that is not "well known and downloaded frequently" and on any certificate without reputation; "If a URL, a file, an app, or a certificate has an established reputation, users don't see any warnings" (https://learn.microsoft.com/en-us/windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/, page dated 23 April 2026, read 7 Oct 2026). SSL.com's code-signing page says Microsoft "moved away from automatic instant reputation", so OV and EV build reputation through use (https://www.ssl.com/code-signing/, 7 Oct 2026). Apple: USD 99 a year, notarisation included (https://developer.apple.com/programs/, 7 Oct 2026); on macOS the unidentified-developer path is System Settings, Privacy and Security, Open Anyway (https://support.apple.com/en-us/102445, 7 Oct 2026). Certum sells an open-source code-signing certificate "from €49.00" (https://shop.certum.eu/open-source-code-signing-on-simplysign.html, 7 Oct 2026; out of stock on the day). Azure Trusted Signing: Basic tier 5,000 signatures a month, one certificate profile of each type; price not shown on the page (https://azure.microsoft.com/en-us/pricing/details/trusted-signing/, 7 Oct 2026; from memory about USD 10 a month, approximate). GPU miners trip antivirus even when signed: T-Rex's README says some engines detect signatures "similar to those that real viruses protected by the same packer have" (https://github.com/trexminer/T-Rex, 7 Oct 2026).
| Step | Today | Proposal | Hours | Gate |
|---|---|---|---|---|
| Mac signature | ad hoc, quarantine strip | Developer ID plus notarisation and stapling in `build-dmg.sh`; the quarantine strip removed | 3 plus the project lead's USD 99 | a fresh macOS 26 machine opens the DMG's app with no Privacy and Security visit |
| Windows signature | none | Authenticode through Trusted Signing or an OV certificate, signed on the box as a job step; the sha256 and the signer's name on the download page (Q50, Q82) | 3 plus the project lead's purchase | a fresh Windows 11 machine runs the installer with no SmartScreen interstitial by the 1,000-download mark (reputation is use; before that the page shows the exact interstitial text and the two clicks) |
| Firewall prompt | UAC 20 to 50 s in, unexplained | the Cards screen names it and the step runs after `setup_done` (Q14) | 1 | the prompt never appears before a screen that says it will |
| Antivirus | nothing | a "What your antivirus may say" line on `/miner#get` with the engine names and the exact action, and the submission to Microsoft's SmartScreen review on every release (the Learn page's submission route) | 1 | the line is on the page; every release's binaries are submitted the day they ship |
| Time to the first share | not measured end to end on a fresh machine | measured on a fresh Windows 11 VM and a fresh Mac for every release by the Devnet 2 gate: download to first accepted share or block, with the clock, the sync and the dataset build as three timed steps | 2 | "first share within 10 minutes of download in 9 of 10 fresh Windows installs", published on `/evidence` |
### 3.2 First run: what the first hour should feel like
Today's three screens (Welcome, Cards, Address, the key sheet) are rated 7 to 8 of 10 by the UI 3 audit; the audit's own finding is that the one question a home miner has, "is this worth running", is not answered until the third screen, and the Cards row does not say what the card is expected to make although `site/miner-priors.json` knows the model (`miner-ui-3-audit.md` 2.1, 2.2).
| Screen | Add | Hours | Gate |
|---|---|---|---|
| Cards | under each known model: "about 25 MH/s at 91 W; on today's network that is about N blocks a day" from the prior and the live network rate | 1 | the row shows a number for every model in the priors file |
| Cards | the tier sentence in plain words: "8 GB: mines; proves small shards", "24 GB: mines and proves" (from `prover-tiers-real-cards.md`) | 0.5 | every memory size has a sentence |
| Address | "Start mining" starts mining; the key sheet comes before the button (the audit: "the button lies once") | 1 | view test |
| Mine, first ten minutes | a "waiting for your first block" line with the live expectation: "a card like yours finds a block about every 1.6 hours on today's network; chance so far: 31 percent" (a Poisson line from the card's own rate and `/api/stats` network rate; the pool mode shows "first share in N s" instead) | 2 | the line is on screen from the first job until the first block, then is replaced by the block card |
The Poisson line is the piece no miner app has. 2miners shows luck for the pool; nothing shows a solo miner's own running chance. It turns the dead first hour into a count-up, and it is honest: it says 46 percent for an 8 GB card at 100 GH/s, which is why the pool switch sits one line below it.
### 3.3 The first block: the card, the sound, the link
Today: an event line in the feed and the blocks strip. Nothing is shareable, nothing is kept.
Proposal, the block card (Ember, Mine page, in place, no dialog):
```
Block 1,284,117 is yours. 12:27:53 UK
RTX 4070 · 25.0 MH/s · 0.025% of the network
80.00 IGN to 0xdd44…86E8 (72 producer points, 8 for signing)
Hash 9f3a…c21e [Open in the explorer] [Save the card] [Copy the link]
```
| Element | Rule | Hours | Gate |
|---|---|---|---|
| The card | shown on the first block of every key, then on every 100th, 1,000th and 10,000th, and on the first block of every new card; stays until dismissed; the rest are feed lines | 2 | view test on the four thresholds |
| Sound | off by default; one short tone on a block when on; honours reduced motion and the OS mute (`app.css` already honours reduced motion everywhere) | 0.5 | the tone never plays when the switch is off |
| Save the card | a 1200x630 PNG drawn locally from the same data (the rig-photo post without the rig; the dark scheme, the brand mark, the card name, the hash, the explorer link as a QR) | 2 | the PNG opens; no network call is made to make it |
| The link | `/block/<hash>` (exists: parents, children, mergeset, shards, checkpoint fractions, `block.html:285-325`) | 0 | |
| What is not on it | no fiat, no price, no "worth": there is no market and the copy law forbids the aphorism | | |
The pool user gets the same card for the first share ("Share accepted by pool-0 · 0.0012 of a block") and the first credited block ("pool-0 found block N; your share 0.41 IGN"), from the `share_result` and the PPLNS credit lines the pool already sends.
### 3.4 The app: Earnings
Today (`miner-ui-3.md` section 5, polish Q18): the first number on the tab is "£0.00 earned: nothing is bought or sold on devnet"; mined IGN is never shown, only proving `paid_wei`; the electricity line is real and shown as a cost.
| Line | Today | Should read | Source of the number | Hours |
|---|---|---|---|---|
| 1 | £0.00 earned | **6,912 IGN a day** at your last hour's rate (86 blocks) | the node's own block count for the key times the subsidy at the block's DAA; the projection from the 1-h rate and `/api/stats` network rate | 2 |
| 2 | 0.0000 IGN from 0 proofs | 2,592 blocks in 30 days, 207,360 IGN; 14 shards, 16.1 IGN | the node and the execution layer (the balance is in the wallet; the app reads the coinbase credits per key) | 1 |
| 3 | none | about £N a day at a price you type (no exchange lists IGN; a typed price, remembered, never fetched) | the user's field; the engine's `price_gbp_per_ign` when a market exists, as the UI 3 plan already owes | 1 |
| 4 | none | your card is 0.100 percent of the network; weight rank 41 of 1,204 keys; 30 of 30 days | `/api/live` miners and the finality weights RPC (`getFinalityWeights`, spec 3.10) | 2 |
| 5 | £1.95 a day electricity | unchanged, and the line under it: "N IGN per kWh" | the existing watt reading | 0.5 |
| 6 | dev fee line | unchanged (1 in 100, the switch) | | 0 |
A rule for every number on the tab: it comes from the node this machine runs, or from the public API with the field named on hover (polish 4.3, one formatter table). The typed price is the only number the user supplies and the tab says so.
### 3.5 The pool
Decision for the launch pool, with reasons:
| Question | Decision | Why |
|---|---|---|
| Who runs it | the project runs pool-0 at the testnet go and at mainnet genesis, on the written systemd unit (`pool/README.md`), with the member's vote key in every header as built | nobody else can on day 1; the member-key design means the project's pool never holds vote weight, which is the thing a project pool is normally criticised for |
| Fee | 1 percent, the same as the solo dev fee, published in `welcome`, on the page and on `/miner` | a 0 percent project pool makes every outside pool unviable, and the first outside pool is a launch gate (section 4.1); 1 percent is what miners accept everywhere (2miners 1.0 percent, https://kas.2miners.com/, 7 Oct 2026; Ethermine 1 percent, approximate); fee-neutral between solo (dev fee 1 in 100) and pool, so the choice is about variance only |
| Where the fee goes | the same software address as the dev fee; it is a software fee, documented as such (`miner-dev-fee.md`), never a protocol fee | no dev fund, no treasury; the protocol carries no fee to anyone |
| Mode | PPLNS, window 2 blocks of weight, payout rounds every 60 s, minimum 1 IGN (as built) | the first payout inside two minutes of the first share for an 8 GB card at 100 GH/s (section 1.4) |
| Default in the app | solo under 500 GH/s network, the app suggests the pool above it, per card: "a card like yours finds a block about every 16 hours on today's network; pool-0 pays every minute" | the Poisson line of 3.2 decides; the user chooses |
| What the pool page shows | the connect card, the lookup, the blocks and the payments table (Q71 owed), luck in MiningPoolStats' convention (Q69, Q72), "payouts follow blue confirmation, not finality" (Q73), and the finality state | the comparator rows in polish 3.6 |
| TLS | before the public testnet (Q67, 8 hours, consensus-engineer) | spec 9.3 |
The variance arithmetic that makes the pool required, computed: a single 8 GB card at 17 MH/s finds a solo block every 1.6 hours at 100 GH/s, every 16 hours at 1 TH/s (23 percent of days with no block), every 6.8 days at 10 TH/s (36 percent of weeks with no block), every 68 days at 100 TH/s. The pool is optional at launch size and required from about 1 TH/s. The pool's own payout latency: credit on blue confirmation (seconds), a round every 60 s, so under two minutes end to end once the member's balance passes 1 IGN.
### 3.6 Community: the Discord, the live page, the leaderboard, the miners page, the explorer
What exists: the Discord kit (roles Founder, Core, Prover, Miner, Bot; channels INFO, CHAIN, LEDGER, TALK; the bot posts a pulse four times a day, a daily digest, weekly numbers, releases, incidents; nothing live yet, Q7); `/live` with a Miners lane list of vote keys with a block in the last 10 minutes; `/miners` the bench table (six rows, Q51); the explorer with Miner as the payout address per block; `/address` (noindex) with balance and blocks mined.
| Surface | Add | Rule that keeps it honest | Hours | Gate |
|---|---|---|---|---|
| Discord #first-blocks | the bot posts every first block of a new key (short key id, the block link, the card model if the miner opted in through the app's "show my card" switch) | from the public API only; the forbidden-string guard; no name, no machine id | 2 | ten first blocks posted on Devnet 2 with the right links |
| Discord roles | Voter (the key is above dust, verified by a message signed with the vote key against `getFinalityWeights`), Window (30 of 30 days), Prover (as built) | chain-side facts, anyone can check the same RPC | 3 | a role granted and revoked by the chain's numbers in a test |
| `/live` Miners | a leaderboard by 30-day weight: rank, short key id, blocks in window, days mined, signing presence, last block; a toggle to the 10-minute view that exists | weight, never hashrate; a renter who arrived today is at the bottom whatever they rent | 3 | the page shows the top 100 by weight with days-mined; a key that stops mining falls one place a day |
| `/address/<key or address>` | the public profile: blocks in 30 days, weight rank, vote state, checkpoints signed, shards proven, first block date, the block cards | noindex stays until the owner opts in from the app ("make my page public") | 3 | the page renders for every key in the window |
| `/miners` | the hardware census (section 4.4): one row per card model from the hourly program's per-card timings, MH/s, W, MH/W, count of keys on that model, median first-block time | measured, scrubbed, no machine names (the bench-table rule) | 4 | eleven rows today, every model with three or more keys after the testnet go |
| Explorer block page | "found by key id N, rank 41, day 23 of 30" under Miner | from the same weights | 1 | the line on every block |
### 3.7 Why I stay: the ladder written into consensus
The thing no other chain has: vote weight is 30 days of blocks per key (rule v2). A level system with no points server, no badge contract and no company database: the chain computes it, the node reports it (`getFinalityWeights`), the wallet verifies the certificates it signs.
| Rung | Name on screen | Rule | Time for a 100 MH/s card at 100 GH/s | Time for an 8 GB card at 100 GH/s | Where shown |
|---|---|---|---|---|---|
| 0 | First block | one blue block with your key | 16.7 min expected | 1.6 h | the block card; #first-blocks |
| 1 | Your key has a vote | 100 blocks in the window (the dust line) | 1.2 days | 6.8 days | Mine hero, address page, Discord Voter |
| 2 | Your signature is in checkpoint K | the first certified checkpoint carrying the key's vote | the next 30-s checkpoint after rung 1 | the same | the finality line in Mine, the block page of the lock |
| 3 | Full window | 30 of 30 days with blocks | day 30 | day 30 | the days ring in the hero; Discord Window |
| 4 | Rank | position by weight among all keys | continuous | continuous | `/live` leaderboard, Earnings line 4 |
| 5 | Signing streak | days since the key last missed the presence window (the 8 points never lost) | continuous | continuous | Earnings: "signing 8 of 80 points, 41 days unbroken" |
| P | Your card proved shard N of block M | a paid shard record | hours on a 24 GB card; not yet on 8 GB | not yet | the Prove tab card, Discord Prover |
The exact lines, in copy law: "Your key has a vote." "Your signature is in checkpoint 184,220." "Your card proved shard 3 of block 1,284,117." "30 of 30 days. Full weight." "Rank 41 of 1,204 keys." Each line names the chain fact behind it on hover (the RPC field), the same rule as every number on the site.
What the rungs pay, so the ladder is not decoration: rung 1 is the vote itself; rung 2 starts the 8-point signing line (the public sentence: miss two hours of signing and the next blocks pay 72 until you sign again); rung 3 is maximum weight; rung P is the proving income (20 points of every block, split by shard). Nothing is paid from a fund; the ladder only names what the rules already pay.
### 3.8 Per tier: the first hour and the first month
Cards at the measured untuned rates of `docs/analysis/prover-tiers-real-cards.md` (rented, 6 October 2026) and the bench table; expectations at 1 block a second; the first month at full rate (100 IGN a block) and at the 90-day ramp approved for the testnet genesis on 7 October (10 percent on day 1, so divide the IGN column by 10 on launch day; CLAUDE.md's 30-day ramp is the earlier text).
Network 100 GH/s:
| Tier | Gap to a solo block | Block in the first hour | Blocks a day | IGN a day (80 points) | Days to a vote | First month: blocks, and what the key is |
|---|---|---|---|---|---|---|
| 8 GB, RTX 4060 (17.07 MH/s) | 1.6 h | 46 percent | 14.7 | 1,180 | 6.8 | 442 blocks; a voter from day 7; full window day 30; proves core-only shards (`prover-tiers` row 4060) |
| 8 GB, RX 9070 XT (17.9) | 1.6 h | 48 percent | 15.5 | 1,237 | 6.5 | 464; a voter from day 7; no proving (CUDA only today) |
| 12 GB, RTX 4070 (24.99) | 1.1 h | 59 percent | 21.6 | 1,727 | 4.6 | 648; a voter from day 5; mines and proves on the patched prover when shipped |
| 12 GB, RTX 5070 (41.89) | 40 min | 78 percent | 36.2 | 2,895 | 2.8 | 1,086; a voter from day 3 |
| 16 GB, RTX 4060 Ti (17.58) | 1.6 h | 47 percent | 15.2 | 1,215 | 6.6 | 456; a voter from day 7; mines and proves |
| 24 GB, RTX 4090 (52.25) | 32 min | 85 percent | 45.1 | 3,612 | 2.2 | 1,354; a voter from day 3; mines and proves today |
| 32 GB, RTX 5090 (98.48 rented; 122 on PC 1) | 17 min | 97 percent | 85.1 | 6,807 | 1.2 | 2,553; a voter from day 2; proves beside the miner |
| Apple M5 Max, Metal (26.7) | 1.0 h | 62 percent | 23.1 | 1,846 | 4.3 | 692; a voter from day 5; proves on the CPU, slowly |
| Rig, 6 x RTX 4090 (313.5) | 5.3 min | 100 percent | 271 | 21,669 | 0.4 | 8,126 (one key per machine, the 6 October default) |
| Pool member, any of the above | first share under a minute; first credit under two minutes | 100 percent | the same blocks on average, paid every minute | the same minus 1 percent | the same days (weight follows the member's own blocks) | the same |
Network 1 TH/s (the same cards):
| Tier | Gap to a solo block | Block in the first hour | Blocks a day | IGN a day | Days to a vote | 30-day blocks |
|---|---|---|---|---|---|---|
| 8 GB, 17.07 MH/s | 16.3 h | 6 percent | 1.5 | 118 | 68 (never inside the window) | 44 |
| 12 GB, 24.99 | 11.1 h | 9 percent | 2.2 | 173 | 46 (never) | 65 |
| 12 GB, 41.89 | 6.6 h | 14 percent | 3.6 | 290 | 28 | 109 |
| 24 GB, 52.25 | 5.3 h | 17 percent | 4.5 | 361 | 22 | 135 |
| 32 GB, 98.48 | 2.8 h | 30 percent | 8.5 | 681 | 12 | 255 |
| Apple M5 Max | 10.4 h | 9 percent | 2.3 | 185 | 43 (never) | 69 |
| Rig, 6 x 4090 | 53 min | 68 percent | 27.1 | 2,167 | 3.7 | 813 |
Per OS and vendor, what differs in the first hour: Windows, two prompts (section 3.1) and NVIDIA through the driver, AMD and Intel through OpenCL; macOS, one prompt, Apple silicon through Metal, no watt reading so no pounds line; Linux and HiveOS, no prompt, the Flight Sheet fields, Hive itself untested on a real rig (`/miner`). AMD cannot prove today (CUDA only). The 12 GB tier cannot mine and prove at once on the shipped build (peak 15.6 GB measured, bench log 5 October); the patched prover's 10.1 GB peak beside the miner on the 4070 is measured and not shipped.
### 3.9 The first withdrawal, and the first "I own something"
No exchange at the testnet, none arranged or sought at mainnet (journey phase 6). So the first ownership moment is not a withdrawal. It is:
| Moment | Today | Proposal | Hours |
|---|---|---|---|
| The balance | in the wallet ("the balance is in the wallet", Earnings); the address page shows balance and blocks | the Earnings tab shows the balance read from this machine's node, with "verified by this node" on hover | 1 |
| The proof | the wallet verifies finality certificates with the node's own code (`finality.rs:101-121`) | the first block card carries "final under checkpoint K, certificate verified by this machine" once the lock lands, and the address page shows the latest locked checkpoint (Q37) | 1 |
| The QR | the wallet draws the `ethereum:` URI locally (`server.rs:140`) | the saved block card carries the explorer link as a QR; the address page's QR under "make my page public" | 0.5 |
| The send | EIP-1559 value transfers in the wallet | a first-transfer card in the wallet: "sent 10 IGN to 0x…, in block N, final under checkpoint K" with the state words pending, included, executed, proven, finalised (UI 3) | 0 beyond Q9 |
"I own something" on Igneum is "a block with my key is final under a certificate my own machine verified". No other chain's miner app says that sentence.
## 4. The exact structure for Igneum
### 4.1 The launch sequence as gates
The go checklist (`docs/plans/testnet-go.md`) has eleven steps, from the seeds at height 0 to the first miner's block 1. These are the community gates that follow it; none has a date.
| Gate | Definition | How it is measured | What opens when it passes |
|---|---|---|---|
| G-C1 First 100 keys | 100 distinct vote keys with a block in the last 24 h | `/api/live` miners over a day | the #first-blocks channel goes live; the leaderboard shows ranks |
| G-C2 First block by a card the project does not own | a block whose key is not in the project's fleet list | the observer's key list against the fleet file (the Discord guard already reads it) | the "first outside block" post, with the owner's permission |
| G-C3 First outside-reproduced benchmark | a card row on `/miners` measured by someone outside the project, with driver, OS and version (Discord rule 6) | the bench-table ingest with `by: reported by a miner` | the census starts (4.4) |
| G-C4 First pool not run by the project | a pool at an address the project does not control with 10 percent of blocks for 7 days, the member key in its headers | the explorer's payout-address share | pool-0 stays at 1 percent; the app's pool list gains a second entry |
| G-C5 First 1,000 independent keys | X5 as decided on 6 October: 1,000 keys above dust over 30 days, independent in autonomous system, machine fingerprint and pool attestation, top-10 share of window weight under 50 percent; a silent key counts only if its AS is its own | the observer's AS and fingerprint columns (owed, one app-owner item) | journey phase 5 closes; mainnet genesis is the next gate |
| G-C6 First outside proving customer | one rollup's job proven and paid on its own chain | the job market's payout contract | phase 4's second half |
### 4.2 The first 1,000 miners: where they come from
The no-airdrop constraint shapes every row: nothing is offered for joining; the only pay is mined emission; the message is the number and the file. Costs are agent hours for the content and the answering; the expected counts are this lane's estimates and labelled so.
| Channel | Expected keys (approximate) | Hours | The message | Rule |
|---|---|---|---|---|
| r/gpumining (the Reddit kit's day-7 post: eleven cards, MH/s, W, MH/W) | 150 to 300 | 6 (post, 48 h of answers) | the card table; "devnet coins have no value; nothing is for sale"; the ledger | rule 2.10 (no referral or promo links); the founder reads the Expanded Rules first |
| r/EtherMining (the Merge story, under rule 7's disclosure) | 100 to 200 | 4 | four years after the Merge, what runs and the command to check it | one linked post per seven days; nobody sent to Discord |
| HiveOS forum and the custom-miner listing | 100 to 250 (rigs, so more hashrate than keys) | 4 plus the first real Hive run | the HiveOS card verbatim, "Hive itself is untested so far; report what breaks" | the first reported rig run gets a bench row and the Miner flair |
| Bitcointalk ANN | 50 to 150 | 3 plus daily answers for a week | the ANN format: no premine, no sale, the dev fee, the card table | no bounty, no signature campaign |
| Miner Discords (lolMiner, BzMiner, Hive, the Kaspa and Ergo mining rooms) | 100 to 200 | 3 | two sentences, the card table, the ledger, "nothing is for sale" | one message per server in its projects channel |
| The miner-software authors (lolMiner, BzMiner, Team Red, Rigel) | 0 to 300 keys on the day one of them ships Igneum | 8 (the worker protocol document, the vectors, the dev-fee template mechanism explained so their fee works in solo mode) | "a fee template is 1 in 100 by a counter; your fee rides the same mechanism" | their fee is theirs; the protocol carries none |
| r/CryptoTechnology, r/zkproofs, r/Monero (the design rooms) | 30 to 80 | 4 | the prover, the verify command, the vs RandomX table | comments only where the rules say so |
| The hardware census itself (4.4), once G-C3 passes | 100 to 300 over the first months (people come to get their card measured on a public board) | 0 beyond the board | "your card's row, measured by the chain, not by us" | scrubbed, no machine names |
| Total | 630 to 1,780 keys, median about 1,000 | 32 | | |
Every row is the Reddit kit's existing text or an extension of it; the only new content is the census board and the worker-protocol document for the miner authors.
### 4.3 The pool at launch
Decided in 3.5: project-run pool-0 at 1 percent, member keys in headers, PPLNS, 60-s rounds, the dev fee off in pool mode because the pool fee is the same 1 percent to the same software address. The outside pool is a gate (G-C4), not a hope: the pool crate is public with its README, and the app's pool field takes any host.
### 4.4 The leaderboard and the census
| Board | Ranks | Never ranks | Source | Why |
|---|---|---|---|---|
| Keys (`/live`, the address page, Earnings line 4) | 30-day weight (blue blocks per key in the window), with days mined and signing presence | hashrate | `getFinalityWeights` | a renter who arrives today has no weight; a laptop that mined for 30 days outranks a rented rig's first week; the board is the chain's own security table, so it cannot lie without the chain lying |
| Cards (`/miners`, the census) | efficiency per card model: MH/s, W, MH/W, and the per-program timing spread from the hourly swap (the frontier lane's "8,760-question hardware census", `frontier.md` 4.3) | people | the hourly program's per-card timings, the bench-table ingest, scrubbed | the public benchmark the litepaper promises, made continuous; a chip that does better than the GPU curve shows up on this board first |
The census is new: RandomX programs are per hash and no pool sees their timing; Igneum's hourly program with per-card racing produces the census as a by-product (`frontier.md` 4.3). It is the one leaderboard a miner wants that no chain has, and it doubles as the chip alarm.
### 4.5 The story each miner tells
Written in copy law (short sentences, no antithesis, no aphorism).
| When | The three sentences |
|---|---|
| First week | "I installed it in five minutes and the first block was mine inside the hour. Every block pays my address straight away. My 4070 is on a public board with its watts." |
| First month | "My key has a vote now. It signs finality every 30 seconds and I can see the checkpoint it is in. After 30 days my weight is full, and the rented farms that showed up last week sit under me." |
| First year | "The program has changed 8,760 times and my card still mines it. My card has proved 400 shards for a rollup I have never heard of. Nothing was sold and nothing was given away: every coin I hold was mined." |
## 5. The surfaces to change
| Surface | Today (polish.md) | Should show | Hours | Gate |
|---|---|---|---|---|
| Ember, Cards | card name, switch, "worker Metal, 40 GPU cores" (audit 2.2) | expected MH/s and W from the priors, "about N blocks a day on today's network", the proving tier sentence | 1.5 | every model in the priors shows a number |
| Ember, Mine (before the first block) | the blocks strip, 10 minutes (`app.js:1052-1127`) | the Poisson count-up line; the pool suggestion when the gap passes 8 h | 2 | the line shows from the first job to the first block |
| Ember, Mine (the block card) | an event line | the block card of 3.3, saved PNG, the explorer link | 4.5 | the four thresholds; the PNG with no network call |
| Ember, Earnings | "£0.00 earned", mined IGN never shown (Q18) | IGN a day, blocks and IGN in 30 days, shards and IGN, a typed price, share of network, weight rank, days, signing streak | 6.5 | every line names its RPC field on hover; a view test per line |
| Ember, Prove | state line "0 assigned · 0 proven · 0 paid" | the shard card "your card proved shard N of block M, 1.15 IGN" | 1 | a card on the first paid record on Devnet 2 |
| Ember, Settings | pool field designed, not built (`pool.md` section 7) | the pool field, the terms box from `welcome`, the dev-fee line reading "off in pool mode: the pool's 1 percent is the same fee" | 3 | a member connects from the app and shows the terms |
| Ember, first run | two prompts, one unexplained (Q3, Q14) | signed and notarised; the firewall step named on the Cards screen | 7 plus the project lead's certificates | 3.1 gates |
| Wallet | one account, no finality state on the address page (Q33, Q37) | the first-transfer card with the five state words; the address page with the latest lock | 3 (plus Q9's 6) | a devnet transfer walks the five words on screen |
| Site `/miner` | "Install. Start. The card mines and proves." plus feature lines | the first-hour timeline (download, the one prompt, first share, first block, first payout) with the measured times from the Devnet 2 gate | 2 | the times on the page equal the gate's log |
| Site `/live` | miners with a block in 10 minutes | the weight leaderboard with days mined and signing presence; the 10-minute view as a toggle | 3 | top 100 by weight; a stopped key falls one place a day |
| Site `/miners` | six rows, two models, "not measured" MH/W (Q51) | the census: one row per model, MH/s, W, MH/W, keys on that model, median first-block time | 4 | every model with three or more keys |
| Site `/address` | balance, blocks, noindex | the public profile of 3.6 behind the app's opt-in | 3 | renders for every key in the window |
| Explorer block page | Miner = payout address | "found by key id N, rank 41, day 23 of 30" | 1 | on every block |
| Pool page | stat strip, connect, lookup, blocks, no payments table (Q71) | payments, luck in the standard convention, "payouts follow blue confirmation, not finality", finality state | 3 | the comparator rows in polish 3.6 |
| Discord | nothing live (Q7); roles Miner and Prover by hand | the bot live; #first-blocks; Voter and Window roles from chain facts | 8 | ten first blocks on Devnet 2 posted; a role granted by a signed message |
| Total | | | 52.5 plus the certificates | |
## 6. What not to build
| Idea | The line that kills it |
|---|---|
| Gamification paid from a fund (a weekly prize, a "block of the day" bonus) | there is no fund; every coin is mined under the 80/20 rule and the signing bonus, and a prize paid by the project is a premine by another name |
| Referral in coins | no referral paid in coins from a fund: there is no fund; and r/gpumining rule 2.10 bans referral codes outright |
| An airdrop for installing, posting or reproducing a benchmark | an airdrop in exchange for anything is a sale by another name; the rule is "nothing is for sale" on every surface |
| NFT badges for the rungs | the rung is a chain fact already (weight, days, signatures); a token for it adds a contract, a market and a price to a thing that must stay a number |
| An off-chain points system | a number a company server has to be trusted for; the ladder's rule is that every number is a chain fact anyone can read from an RPC |
| A rank-by-hashrate board | a renter tops it on the first day; the only board is weight, which takes 30 days |
| A "top earners" board in fiat | there is no price; a typed price is the user's and stays on their machine |
| A Discord level bot (MEE6-style XP for messages) | a number a server owner sets; it rewards talking, not mining |
| A bounty for the first ASIC, or a device bounty | ruled out (M1, M22); a device bounty is a sale of the chip |
| Streaks that penalise a miss (lost rungs, demotion) | the signing bonus already prices a miss (72 until you sign again) and nothing is burned; a second penalty on top is the burn the owner refused |
| Any surface whose number needs a company server to be trusted | the observer, the API and the Discord bot are conveniences; every number they show must be reproducible from a node, or it is not shown |
## 7. Verdict table
| Proposal | Evidence (chain, year, number) | Newness | Hours | Gate | Recommend |
|---|---|---|---|---|---|
| Signed and notarised installers | SmartScreen warns on any file without reputation (Microsoft Learn, 2026); polish Q3 | everyone has it; we lack it | 7 plus certificates | no interstitial on a fresh Mac; the Windows one gone by 1,000 downloads | do now |
| The Poisson count-up before the first block | 2miners shows pool luck (kas.2miners.com, 2026); no app shows a solo miner's own running chance | nobody has it | 2 | the line shows until the first block | do now |
| The block card with a saved PNG | EtherMining's rig photo 2,528 points in 2021 (section 1.1); the Helium miner photo 860 in 2021 | nobody has it in a miner app (approximate) | 4.5 | PNG with no network call | do now |
| Earnings in IGN first, a typed price second | NiceHash shows fiat first (polish 3.1, approximate); Q18 | someone has fiat; nobody has "typed price, never fetched" | 6.5 | every line names its field | do now |
| The weight ladder: vote, signature, full window, rank, streak | rule v2 (Igneum, 2026): weight is 30 days of blocks per key | nobody has it | 6 (across Ember, address page, Discord) | a Devnet 2 key walks every rung on screen | do now |
| The weight leaderboard on `/live` | Kaspa pools rank workers by hashrate (approximate); Helium ranked hotspots by HNT (section 2) | nobody ranks by consensus weight | 3 | top 100 by weight | do now |
| The hardware census on `/miners` | frontier 4.3; the litepaper's promised benchmark | nobody has it | 4 | every model with three keys | do now |
| Pool-0 at 1 percent, member keys | 2miners 1.0 percent fee (2026); spec 09 member votes | the member-key pool is new; the fee is standard | 0 beyond Q67 to Q73 (about 20) | G-C4 | do now |
| #first-blocks and the Voter and Window roles | Discord kit roles (2026); chain-side facts | nobody grants a role from consensus weight (approximate) | 5 | roles from a signed message | do now |
| The public address profile behind an opt-in | Helium's explorer hotspot page (2021), section 2 | someone has it (Helium); ours adds the vote and the signatures | 3 | renders for every key | prototype |
| The first-hour timeline on `/miner` with measured times | the devnet laptop's 7 minutes and the 5090's first minute (bench log, 4 Oct 2026) | ethereum.org and kaspa.org have no measured install time (approximate) | 2 | the page equals the gate's log | prototype |
| The worker-protocol document for miner authors | lolMiner 0.75 percent Kaspa fee, T-Rex 1 percent (their READMEs, 2026) | standard | 8 | one outside miner ships Igneum | prototype |
| A dust line that scales with the network | section 1.4: an 8 GB card never votes past about 500 GH/s | a finality-lane question | 0 here | the finality lane's answer | watch |
| Sound on a block | every pool page has a block sound option (approximate) | standard | 0.5 | off by default | watch |
| Anything in section 6 | | | | | never |
## 8. Three headline findings for the coordinator
1. At the litepaper's 100 GH/s network a solo 8 GB card finds its first block in 1.6 hours expected and 46 percent of them see no block in the first hour, so the first-hour dopamine for the most common tier is the Poisson count-up line and the pool's first share under a minute, not the block; at 1 TH/s that card finds a block every 16 hours and never reaches the 100-block vote line (44 blocks in 30 days), which the finality lane must weigh against the 1,000-independent-keys gate.
2. Igneum's 30-day vote window is a level system no other chain has, and it is free: the rungs (first block, 100 blocks for a vote, a signature in a checkpoint, 30 of 30 days, rank by weight, a signing streak) are chain facts from `getFinalityWeights`, cost about 6 agent hours to show across Ember, the address page and Discord, and cannot be topped by a renter inside 30 days.
3. In a 105-post sample of miner joy on Reddit (69 with a room median), the posts that rise highest are the miner's own: "my card paid for itself" at 777 times the room's typical score, the rig photo at 417, the hashrate milestone at 409, against 66 for the network's own milestone and 56 for the first pool payout; so every shareable surface Igneum builds carries the miner's card, rank and days, not the project's number, and the saved block card (4.5 hours) is the first of them.
## Sources
Repository files (the mission worktree, read 7 October 2026): `CLAUDE.md`; `docs/analysis/horizon/polish.md` (sections 1, 3.1, 3.2, 3.4, 3.6, 3.7, 3.10, 4.5); `docs/analysis/vote-or-burn.md` section 5; `docs/analysis/tail-emission.md`; `docs/analysis/horizon-2026-10.md` section 1; `docs/plans/ledger-decisions.md` (item 3, the standing decisions, the 6 and 7 October decisions); `docs/plans/pool.md`; `pool/src/config.rs`; `docs/spec/09-pool-protocol.md`; `docs/plans/miner-ui-3.md` and `miner-ui-3-audit.md`; `docs/plans/testnet-go.md`; `docs/design/miner-dev-fee.md`; `docs/community/discord-hooks.md`; `docs/analysis/prover-tiers-real-cards.md`; `docs/analysis/horizon/frontier.md` 4.3; `docs/bench-log.md` (4 and 5 October 2026 entries); `site/journey.json`, `site/live.html`, `site/explorer.html`, `site/miner.html`, `site/miner-bench.json`; the litepaper text; the Reddit kit on branch `reddit-kit` (`docs/community/reddit/outreach.md`, `outreach-week-1.md`, `discord.md`).
Fetched by this lane (all 7 October 2026):
- https://2miners.com/faq (payouts every 2 hours; thresholds per coin page)
- https://kas.2miners.com/ (1.0 percent fee, 50 KAS minimum, 771 miners, luck 441 percent, last block 2 minutes ago)
- https://solo-kas.2miners.com/ (SOLO fee 1.5 percent, 99 miners)
- https://p2pool.io/ (min payout 0.00027 XMR; "several days to a week to find a share")
- https://github.com/Lolliedieb/lolMiner-releases (Kaspa fee 0.75 percent, Autolykos 1.5 percent)
- https://github.com/trexminer/T-Rex (1 percent, 2 percent on Octopus and Autolykos2; the antivirus note)
- https://learn.microsoft.com/en-us/windows/security/operating-system-security/virus-and-threat-protection/microsoft-defender-smartscreen/ (page dated 23 April 2026)
- https://www.ssl.com/code-signing/ (reputation through use for OV and EV)
- https://support.apple.com/en-us/102445 (Open Anyway)
- https://developer.apple.com/programs/ (USD 99 a year) and https://developer.apple.com/support/compare-memberships/ (notarisation included)
- https://shop.certum.eu/open-source-code-signing-on-simplysign.html (from EUR 49, out of stock)
- https://azure.microsoft.com/en-us/pricing/details/trusted-signing/ (Basic 5,000 signatures a month; price not shown)
- https://en.wikipedia.org/wiki/Helium_Network and https://en.wikipedia.org/wiki/Chia_(cryptocurrency)
- https://api.pullpush.io/reddit/search/submission/ (r/EtherMining, r/chia, r/HeliumNetwork, r/kaspa listings used as a cross-check of the sub-lane's sample)
Fetched by the Reddit sub-lane (scratch `mission-reinvent/reddit-sample.md`, 105 posts, every URL in its table 1 and quotes in table 3; the Arctic Shift archive for medians; the ninjastic archive for bitcointalk). The URLs cited in sections 1.1 and 2 above are from that file.
Fetched by the chains sub-lane (scratch `mission-reinvent/chains.md`, 96 URLs in its sources list): the Helium HIPs 10, 15, 17, 20, 25, 51, 53, 54, 70 and the denylist repository; the Chia blog posts of 11 Nov 2020, 23 Feb, 17 Mar, 24 May, 13 Jun, 15 Jun, 30 Jun, 7 Jul, 3 Aug 2021 and 19 Mar 2022 and releases 1.0.0, 1.1.0, 1.2.0; Etherscan's hashrate CSV; bitinfocharts ETH and ETC; Decrypt on ETC; api.kaspa.org; the BzMiner, lolMiner and Team Red release pages; asicminervalue; the Monero node RPC, xmrchain, the RandomX repository and getmonero.org; the Ravencoin whitepapers, releases and blockbook; the Ergo releases, docs and explorer API; the 2miners stats APIs and blog; CoinGecko for every price. Pages that refused the fetch (Mashable, The Verge, Bloomberg, Forbes, CNBC, Polygon, PCMag) are cited through Wikipedia and marked so in that file.
Figures labelled approximate come from memory and were not pinned to a page today.

View file

@ -0,0 +1,371 @@
# The last mission, lane 2: started and not finished, across the industry
7 October 2026. Lane 2 of the final research programme. What the industry started and did not finish, group by group, with one verdict per row: Igneum already has the finished version, Igneum could finish it in hours, or Igneum should leave it. Every figure from a source carries its URL and access date in section 9; every figure from memory is labelled approximate. Hours are agent hours (the project lead's rule: Claude-side work takes hours, never weeks). Nothing here is a token sale.
What this file does not repeat: the ASIC chip history (`docs/analysis/asic-resistance-history.md`), the useful-work verdict and the stored-state candidate (`new-pow.md` sections 3, 6, 7), the ranked frontier ideas (`frontier.md` section 0, 3.10, 3.11), and Igneum's own pool design (`docs/plans/pool.md`, `docs/spec/09-pool-protocol.md`). Those are cited, not restated.
## 0. Progress (UK time)
| Time | State |
|---|---|
| 08:1x (approximate) | Context read: CLAUDE.md, asic-resistance-history.md, new-pow.md 3, 6, 7, frontier.md 0, 3.10, 3.11, horizon-2026-10.md 1, pool.md, spec 09, polish.md 3.1, 3.6, 3.10 |
| 08:2x (approximate) | Four research lanes launched (A, B, C with D, E). Lane F was refused by the concurrency cap and was researched by this lane directly |
| 08:3x (approximate) | The session's WebSearch budget ran out (200 of 200). Every later fact came from WebFetch of a primary page or is labelled approximate |
| 08:49 | Lane F notes saved (scratch `mission-unfinished/F-notes.md`, file time) |
| 08:50 | Igneum-side pool and Ember comparison drafted (scratch `igneum-side-draft.md`) |
| 08:53 to 08:59 | Lanes A, E, B, C with D landed (scratch file times) |
| 09:09 | All notes read; assembly of this file started |
| 09:17 | File complete: 371 lines, em-dash grep at zero, nothing staged |
Limits of this research: p2pool.observer answered 502 all morning (Monero P2Pool share taken from the miningpoolstats data file instead); Bob Rao's ProgPoW PDF would not extract (his 1.1x to 1.2x figure is cited to EIP-1057); Bitmain's own X9 page was unreachable (the X9 is reported as announced per resellers, unconfirmed shipping); NiceHash's fee and repayment pages are gone (those figures are approximate); Salad's take rate is not published anywhere fetched.
## 1. Group A: proof of useful work
The one question per row: can the useful work be verified cheaper than it is done, and is it sampleable (a nonce picks a random instance the miner cannot steer, with tunable hardness)? The third column the rows keep answering by themselves is whether anyone wanted the output.
### 1.1 The rows
| # | Programme | Attempted, by whom, when | Achieved (numbers) | Left undone | Why it stopped | Verified cheaper than done | Sampleable |
|---|---|---|---|---|---|---|---|
| 1 | Primecoin | Sunny King, 7 Jul 2013: header hash is the origin of a Cunningham or bi-twin prime chain | 13-prime 94-digit chain 10 Sep 2013; first length-15 twin chain 30 Mar 2018; height 7,038,822 today | Any use of the primes; GPU resistance (GPU miners by 2014, approximate) | Nobody needed the output; price USD 0.034, "stopped trading on all exchanges"; last release 26 Jan 2021 | Yes, but polynomial: 10 to 15 modexps to verify against millions of sieve steps (approximate) | Yes: the hash fixes the origin, chain length plus fractional remainder tunes hardness |
| 2 | Gridcoin | Rob Halford, "Proof of Research" live 11 Oct 2014 on BOINC credit | 17 whitelisted projects, 3 greylisted; release 5.5.0.0 on 3 Apr 2026 (78 PRs, 11 contributors) | A verifiable work primitive; consensus moved to pure PoS 2014 to 2015 | Scraper nodes read credit from project servers and sign a superblock; the chain never checks a work unit | Only by trust (an oracle reads a website) | No: the miner picks the project and the unit; the project sets hardness |
| 3 | Curecoin, FoldingCoin | 2014, Folding@home points paid daily (CURE) or monthly (FLDC on Counterparty) | 1 trillion F@h points by 28 Jul 2019, over 10,000 team members | Verification by anyone but Stanford's servers; Curecoin 2.0 roadmap undated; FoldingCoin asset archived, site gone | Tip jar on a centralised stats feed; token value fell under the electricity (approximate) | Only by trusting F@h | No: F@h assigns the work |
| 4 | Aleo PoSW to synthesis puzzle | Proof of Necessary Work (Kattis, Bonneau, 2020/190); testnet 3 coinbase puzzle 2023; mainnet 17 Sep 2024 on AleoBFT with the puzzle outside consensus; ARC-41 synthesis puzzle | 750 M proofs per second and over 44,000 provers on testnet 3 (Messari excerpt); 2/3 of coinbase to provers; about 16 pools took close to 90 percent of puzzle rewards; ARC-46 (31 Jul 2025) demands 100,000 ALEO staked per solution, 2,500,000 by 2027 | The original promise: energy that produces proofs of real state. The puzzle proves nothing the network uses | A BFT validator set gives finality; the puzzle survives only to pay hardware and keep a prover fleet warm; proving centralised on the same path as mining | Yes (SNARK verify in milliseconds) | Yes (epoch hash plus nonce, target tunable). Useful: no |
| 5 | Ofelimos | Fitzi, Kiayias, Panagiotakos, Russell, eprint 2021/1379, CRYPTO 2022: doubly parallel local search, every step a hashed PoW unit | A security proof in the backbone model; WalkSAT variant "competitive with vanilla WalkSAT" | Any deployment; who submits problems and pays; the search's own efficiency (FRLS follow-up 14 Nov 2025 calls DPLS "particularly wasteful") | Economics and operations, not the proof | Yes (each step is a cheap check) | Partly: the step is nonce-bound, the instance comes from a client pool, so hardness is tuned on the hash part |
| 6 | PoW from worst-case assumptions | Ball, Rosen, Sabin, Vasudevan, eprint 2017/203 and 2018/559: Orthogonal Vectors, 3SUM, APSP with a delegation verifier | The conditions: worst-case to average-case reduction, non-amortisability, fast verification | Any implementation or benchmark; a buyer for random OV instances | The instances must be drawn from a distribution no real problem has; polynomial blow-ups | Yes (near-linear verify against quadratic solve) | Yes by construction. Useful: no in practice |
| 7 | Filecoin PoRep and PoSt | Protocol Labs, mainnet Oct 2020: seal a 32 GiB sector (hours of CPU plus 20 to 30 min GPU SNARK, 128 to 256 GiB RAM), then daily WindowPoSt | Utilisation 29 percent (Q1 2025), 36 percent (Q3 2025), 1,110 PiB of real data on 3.0 EiB committed; raw byte power 3.01 EiB (29 Sep 2025) to 1.35 EiB (14 Sep 2026), down 55 percent; 99.5 percent of Q3 2025 fees were penalties | Paid demand; two thirds of proved bytes were zero-filled capacity; the chain now pivots to PDP hot storage (May 2025) that earns no consensus power | Sealing cost was paid by emission, not customers; when rewards fell providers left | Yes (one seal, then a sub-second daily proof) | Yes (random leaf challenges per deadline). The only row that held both for a real good, at hours per 32 GiB |
| 8 | Chia proof of space | Chia Network, mainnet May 2021: plots of random tables, challenge per signage point | 1.5 EiB to 15 EiB in May 2021 alone, peak 36.5 EiB Jul 2021; a k32 plot needs 1.3 TiB of SSD writes; pooling Jul 2021; compression Jan 2023; under 4 EiB effective and under 3 EiB raw in Sep 2026 (about 10 percent of peak); XCH USD 1.36 against a USD 1,934.51 peak; Chia 3.0 (27 Feb 2026) resets plots to 1 GiB k28 with a 256-day phase-out | Anything stored; the space holds nothing | Price down 99.9 percent, reward per TB collapsed, no use for the plots | Yes (a few hashes) | Yes (challenge, plot filter, k). Useful: no |
| 9 | Flux, Akash | Compute markets beside a coin: Flux (2018 as ZelCash, 7,015 nodes on 5 Oct 2026 against a 14,000 peak, no published revenue in six years, "PoUW v2" Oct 2025 = hardware benchmarking); Akash (Q1 2026 lease revenue USD 253,250, 58 providers, 84 GPUs in use of 334) | Node counts, not verified work | A chain that checks the compute; InFlux Technologies entered administration 4 Sep 2026 | Block rewards pay for idle capacity; demand is two to three orders under the subsidy | No (reputation and benchmarks) | No (customers pick the job) |
| 10 | Dynex | 2022 to 2026, "neuromorphic quantum computing cloud", DynexSolve | A WIPO patent (14 Nov 2024); market cap USD 119,386, down 99.9 percent; a "phase-out of the utility token" toward a securities structure | A checkable claim: no public code shows the chain checking that a QUBO instance was solved | The useful-work claim was never made verifiable | Unknown, treat as not verified | Not sampleable |
| 11 | Qubic | 2024 to 2025 "useful PoW" (Aigarth training); from Jun 2025 the work was Monero RandomX hashing sold for QUBIC buybacks | Under 2 percent of Monero in May 2025, over 25 percent by late Jul, 51 percent claimed 11 to 12 Aug 2025; 63 of 122 blocks (3,475,729 to 3,475,850); 6-block reorg 12 Aug (about 60 orphans); 18-block reorg 15 Sep 2025 (117 transactions, past Monero's 10-block lock) | Any verification of the AI claim; no Monero consensus change by Sep 2025; miners moved to P2Pool, exchanges raised confirmations | The "useful" work was a token buyback funded by attacking another chain | The RandomX part: yes, and useless by design. The AI part: no | The AI part: no |
| 12 | Bittensor subnets | 2023 onward, validators score miners off-chain, Yuma consensus; dTAO 13 Feb 2025 | Over 120 subnets (Mar 2026); 24 with commercial income, USD 28 M to 35 M ARR estimated (Sep 2026); validator reward correlates with stake at 0.80 to 0.95, miner reward with performance at 0.10 to 0.30 (64 subnets, 6.66 M events); weight copying fixed by commit-reveal (May 2024); Quasar (SN24) collapsed Aug 2026 on a plagiarised model | Proof of anything; usefulness is judged, not proved | By design: a stake-weighted reputation market with emission attached | No (judged) | Partly (validators pick queries, no nonce, no hardness knob) |
| 13 | Proof of inference, 2024 to 2026 | Gensyn Verde (refereed delegation, about 60 percent overhead on Llama-3.1-1B, needs one honest provider); Hyperbolic proof of sampling (re-execute a fraction, slash); Ambient proof of logits (claimed 0.1 percent overhead, testnet still pending Apr 2026); Inference Labs (self-reported 950 M proofs); zkML (hundreds of seconds per query for billion-parameter models); Boundless PoVW (pays ZKC per proved cycle, a sample proof 2 to 5 min at USD 0.04 to 0.17); Succinct (over 6 M proofs in 2025, 25 provers) | Proving networks exist and are run by a few dozen operators | A job that is both random and wanted; a verifier cheaper than a referee, a chip or a slashing game | zk proving costs 10^3 to 10^4 times the inference; the cheaper schemes trust something | zk: yes at 10^3 to 10^4 overhead. The rest: only by trust | zk: yes if nonce-bound. Nobody has made the job random and wanted |
The 2025 to 2026 literature says the same thing from three sides. The SoK (eprint 2025/1814, over 50 constructions): "PoUW is actually not as useful as expected, since the economic and societal utility do not contribute to the security budget". Pass (arXiv 2606.06700): a majority attack still costs the block reward. Basu (arXiv 2606.04819): Pearl's 24 EH/s network of about 320,000 GPU-equivalents at about 112 MW "produces zero useful AI computation".
### 1.2 The pattern, and what Igneum finishes
Every programme that passed both tests (cheap verify, sampleable with tunable hardness) did so by making the work useless: Primecoin chains, Chia tables, Aleo's synthesis puzzle, Filecoin's capacity sectors, Boundless cycles. Every programme that kept the work useful gave up verification: Gridcoin, Curecoin, Bittensor, Flux, Akash, Qubic, Dynex. Filecoin alone held both for a real good and paid with hours of sealing per 32 GiB and a network two thirds filler.
**What Igneum already finishes (two rows).**
| Row | The unfinished promise | Igneum's finished form | Evidence in the repo |
|---|---|---|---|
| 4, Aleo PoSW and Proof of Necessary Work | Energy that produces succinct proofs of real state, paid from issuance | Every block is proven by miners in chunks and aggregated 20 to 60 s behind the tip; the provers are paid 20 percent of emission by sortition by weight; the proof is of the chain's own execution, not a synthetic circuit | CLAUDE.md design paragraph; lane 4's finding 1: the proof verified in consensus is the fix for the one line where a majority earned more than it spent (11,636 IGN an hour at 51 percent of blocks); switch `proving_consensus_verify_daa` ships off by default in 0.3.16, activation a decision owed |
| 13, Boundless PoVW and Succinct | Pay per verified unit of proving, meter the cycles, let a market set the price | pgas cycle metering through the proving share; external jobs 90/10 provers and burn, priced in dollars, settled in the token | frontier.md 3.10 "PoVW-like cycle metering through pgas"; CLAUDE.md fee lines |
**Why the split is the finished form.** The bound from `new-pow.md` 3.1 is the reason nobody closed the loop: the useful fraction of a proving-as-lottery scheme is (proving work per segment) over (network hashes per segment), 8 percent at 1 GH/s and 0.08 percent at 100 GH/s, because gas sets one and the security budget sets the other. Aleo found the same wall and decoupled on 17 Sep 2024 ("provers do not participate in consensus or produce blocks"), then had to add a stake gate in 2025 because the puzzle centralised on the fastest prover. Igneum's split carries no stake and no coupling: the lottery is a Poisson process on a random program (the Kaspa developer's objection in frontier 3.10 stays satisfied), the proving is paid by sortition by weight, and the one line where the split was NOT yet finished (a majority prover pool earning more than it spent) is closed by verifying the proof in consensus. Until that switch is on, Igneum's split is Aleo's 2024 form; with it on, it is the form Aleo could not reach without a validator set.
**What Igneum should leave.** Rows 1 to 3, 5, 6, 9 to 12: 0 hours. The only adjacent idea with value was taken by lane 8 as scheme C (the dataset is the keyed execution state, the class v5 candidate), which answers rows 7 and 8 by making the stored thing the chain itself, at an unchanged hash rate; it is already judged and not repeated here.
## 2. Group B: memory-hard and ASIC-resistance programmes that stalled
The chip history is done in `asic-resistance-history.md`. This section covers only what was started and abandoned, and ends each row with what Igneum's hourly random program, latency shadow and class ladder already encode, and what they do not.
### 2.1 The rows
| # | Programme | What was planned | What shipped | What was left on the table | Why it stopped |
|---|---|---|---|---|---|
| 1 | Ethash successors | EIP-969 (David Stanfill, 3 Apr 2018): five FNV primes of Hamming weight 7 to 8 against the Antminer E3, fork at block 5,550,000 with 30 days' notice; ProgPoW as "Ethash 2" | Nothing on Ethereum. ETC's Etchash (ECIP-1099, Thanos, block 11,700,000, Dec 2020) halved DAG growth to keep 3 to 6 GB cards | The FNV tweak (Stagnant), the DATASET_PARENTS increase Least Authority asked for, any epoch recalibration on mainnet | No client team adopted EIP-969 for a chip expected to be short-lived; attention moved to ProgPoW; PoW ended at the Merge 15 Sep 2022 |
| 2 | ProgPoW, EIP-1057 | Hold the chip gain to 1.1x to 1.2x by saturating the whole GPU datapath (random math, 16 KB cache, DAG loads, keccak-f800) | Two audits (Least Authority 9 Sep 2019: accurate to design, five suggestions, the light-evaluation attack named; Bob Rao: 100 MB on-die SRAM "possible", DRAM 3 pJ per bit against 0.3 on chip); KawPow (6 May 2020), FiroPoW (26 Oct 2021), Zano, Sero, Quai (29 Jan 2025) | Activation on Ethereum: tentatively accepted 4 Jan 2019, "accepted and final" 21 Feb 2020, petition EIP-2538 27 Feb, kik's 64-bit-seed exploit about 4 Mar, off the fork schedule 6 Mar 2020; authors reposted it 11 May 2020 saying "we do not recommend" deployment | Governance (a revival read as stealth), the PoS roadmap, a bug two weeks after "final", the authorship conflict (Core Scientific, Linzhi's 3x to 8x claim with no evidence) |
| 3 | RandomX v2 | A tweak after seven years: program 256 to 384 instructions, 16 AES mixes in place of XOR, dataset prefetch 2 iterations ahead; work per hash up 52.9 percent (4,456,448 to 6,815,744 ops) to re-match CPU to memory latency | Library PR 317 merged 17 Feb 2026 (SChernykh); commitments PR 265 merged 8 Sep 2023 | Activation: Monero PR 10038 (v17) open since 14 Aug 2025, pending review 19 Sep 2026, no date | The chip came first: Antminer X5 Sep 2023 (212 kH/s, 1,350 W); X9 1 MH/s at 2,472 W listed as "August 2026, delayed" per resellers, unconfirmed shipping; the Qubic episode used plain CPUs so it forced no algorithm change |
| 4 | Kaspa kHeavyHash | A hash for optical hardware (Dubrovsky, Ball, Penkovsky, arXiv 1911.05193): shift cost from OPEX to CAPEX; GPU resistance never a goal; chosen by community vote one day before launch | IceRiver KS0 (100 GH/s at 65 W, 2023), then 15 to 21 TH/s boxes; GPUs at 2.2 GH/s left | A GPU lane (never planned); optical mining (no shipping hardware, approximate) | By design. The GPU fleet forked away: Karlsen (FishHash, 4 GB DAG), Spectre (CPU), Pyrin |
| 5 | Autolykos v2 | Keep the 2 GB table, grow it 5 percent per 51,200 blocks from block 614,400, cap at block 4,198,400 (2,143,944,600 elements) | EIP-0009 at block 417,792 (Feb 2021 approximate); non-outsourceability removed because contract pools bypassed it (Chepurnoy and Saxena, eprint 2020/044) and small miners did not want it | A successor to pool resistance; an answer to HBM FPGAs ("HBM FPGA friendly", Osprey listed ERGO); the growth stops at the cap | Small prize, no chip, the table cap is a policy choice |
| 6 | Grin's two lanes | Cuckaroo29 for GPUs (90 percent of reward falling to 0 over two years, tweaked every six months), Cuckatoo31+ for chips (10 percent rising to 100) | Four hard forks on schedule; HF4 (about 15 Jan 2021) ended the GPU lane; one chip shipped (iPollo G1, 36 GPS at 2,800 W, Dec 2020) | Obelisk GRN1 cancelled 19 Jul 2019 ("lack of interest and funding", full refunds); Innosilicon G32 announced, never documented shipping; the lean-solver memory claim: Tromp's USD 10,000 linear TMTO bounty claimed 11 Apr 2025 (about half an order of magnitude, not tenfold) | The schedule forced chip makers to choose between a single-use C31 chip and a late C32 chip at a USD 2 coin; network today 3.40 KGps on GPUs |
| 7 | Equihash parameter programmes | Zcash: a parameter change "ideally deployed by late 2018"; a 2020 PoW migration (ballot 3 Jul 2018: 38 of 64 for migration by 31 Dec 2020). Beam: forks at 6 and 12 months then an "affordable ASIC" (BeamHash III, 28 Jun 2020). BTG: Zhash 144,5 after the May 2018 51 percent attack (388,000 BTG) | Zcash stayed on 200,9 with chips (2019: BCTV14 forced the choice of Sapling over ASIC work); Beam stayed on BeamHash III with GPUs only; BTG forked and was hit again in Jan 2020 | Zcash's migration; Beam's affordable chip; BTG's real problem (rented hash on a small chain) | Governance by poll chose "reduce chokepoints" over resistance; parameter forks do not fix a rentable chain |
| 8 | Octopus to Ethash | CIP-102 (Chenxing Li, 5 Aug 2022): switch to Ethash "to make it easier for Ethereum miners to switch to Conflux" | Nothing; the CIP has "TBA" for specification and rationale and never left Draft | The AMD support and DAG shrink the forum asked for instead | The community called Ethash "not ASIC resistant" and Octopus "the trademark" |
| 9 | Blake3 on Alephium | ASIC friendly by design, "just like Bitcoin" | Goldshell AL-BOX (360 GH/s, May 2024 per the aggregator), Antminer AL1 (15.6 TH/s, Jul 2024); the project's own gpu-miner and fpga-miner repos stopped mattering | Nothing, by the project's own view | By design |
| 10 | Tensor PoW | Komargodski and Weinstein, eprint 2025/685: PoUW from arbitrary matrix multiplication at 1+o(1) overhead; "this blockchain is currently under construction" | A paper (15 Apr 2025, revised 8 Dec 2025). ethresear.ch has no topic matching "tensor core proof of work" | A chain; a measurement of what tensor work costs the honest card against a chip | Nobody measured it before writing it |
### 2.2 The FPGA question, one line per row
| Row | Was the FPGA the first adversary | What stopped it |
|---|---|---|
| Lyra2REv2 (Vertcoin) | Yes: a Zynq UltraScale+ at 31.25 MH/s and 24.93 W, 4.3x a Titan Xp per joule (arXiv 1905.08792) | A fork to Lyra2REv3 |
| X16R (Ravencoin) | Yes: all 16 hashes on one UltraScale+, about 5x a 1080 Ti per joule at 3 to 4x the price | X16Rv2 then KawPow |
| Equihash 144,5 and 200,9 | Promised in 2018 (a vendor asked a USD 1,000,000 minimum order), no hashrate ever posted | The 2.5 GB table; HBM boards matched GPUs per dollar at best (approximate) |
| Ethash and ProgPoW | HBM boards existed in 2019; Least Authority: a 10-block period makes "building and loading a bitstream in such a short period (about 2 minutes) impractical" | DRAM latency on cheap boards, HBM cost on fast ones, bitstream churn |
| Autolykos v2 | Osprey listed ERGO on an 8 GB HBM board; no share figure published | Nothing stopped it; nothing measured it |
| kHeavyHash | Osprey E300, 14 GH/s at 250 to 500 W, USD 4,999, three VU35P with HBM2, announced 13 Dec 2022 | Overtaken within months by 100 GH/s to 1 TH/s ASICs |
| RandomX, Cuckoo | No FPGA product ever shipped | A CPU-like core with 2 MB per thread; 512 MB to 1 GB of fast memory per graph |
### 2.3 What Igneum already encodes, and what it does not
| Row | Encoded in Igneum (where) | Not encoded (the gap) |
|---|---|---|
| 1 Ethash successors | A dataset that grows on a genesis-fixed schedule with the cache doubling (256 MiB, 512 MiB year 4, 1 GiB year 12); the 4 GB cliff lesson lives in the tier rule ("every number carries its consequences", 8 GB to 32 GB cards); EIP-969's human tweak against a chip is replaced by automatic era draws | The DATASET_PARENTS idea is Igneum's mixer x8 (8 dependent reads per item), which has the fixed shape the chip history calls the 3x factor; the random item derivation (asic-history addition 2) is still open |
| 2 ProgPoW | The governance death is designed out: every layer is a genesis rule or a reserve, no adoption vote (asic-history lesson 7); the 64-bit-seed class: Igneum's seed is 256 bits and the program is the epoch's; the light-evaluation attack is priced (chip-model-v3, 0.31x bare, 0.92x with the 3x factor); the datapath target is the whole GPU | ProgPoW's 2-minute period was its FPGA defence; Igneum's epoch is 1 h, so a soft-overlay bitstream within the hour is the open lane (asic-history addition 5, the 10 min to 2 h epoch reserve, design on `ca2-epoch`) |
| 3 RandomX v2 | The lesson is that a tweak after seven years arrives after the chip. Igneum draws era parameters every 6 months from chain state and unlocks families by height, with no human release; the class ladder (95 percent with a floor height, P2) is the only human path and it is for new code, not for parameters | Per-hash program entropy (RandomX's 25x GPU cost, refused on purpose); the random superscalar item derivation; four external audits before launch (RandomX paid USD 141,000; Igneum's cryptanalysis spend of USD 80,000 to 160,000 is a decision owed) |
| 4 kHeavyHash | The loss of the GPU fleet is the metric: hashrate share by card model from the observer and the January 2027 benchmark (asic-history addition 4) | A published vendor-share number does not exist yet |
| 5 Autolykos v2 | Pools are wanted (spec 09), so non-outsourceability is nowhere by choice; the dataset grows by rule | Whether Igneum's growth schedule ever caps is a spec 1.13.3 question this lane did not reopen |
| 6 Grin | Scheduled change without a vote is the shared idea; Igneum's draws are automatic, Grin's were forks | The lean-solver lesson (a memory claim weakened six years later by a bounty) is the reason the mixer and chained cache need cryptanalysis (ledger M7) |
| 7 Equihash | The rented-hash problem is answered by the 30-day weight finality, not by the hash (section 4) | Nothing |
| 8, 9 Octopus, Blake3 | Nothing to take | Nothing |
| 10 Tensor PoW | Measured and retired: scheme B's mm8 shadow costs the honest card 0.056 to 0.70 pJ per multiply-add and moves the chip's edge only from 6.9x to 4.9x, so it is reserve R8 with the two-output correction (new-pow.md 6) | Nothing; Igneum did the measurement the 2025 paper has not |
| FPGA, all rows | Bitstream churn is encoded as the hourly program; the HBM board is the f = 1 stored-dataset chip in the model (5.1x on GDDR7, 7.5x to 9.2x on HBM3) | The soft-overlay FPGA miner with HBM is unmeasured (addition 5); no row in the chip model for a partial-store chip (addition 1) |
Verdict for the group: nothing in B is a programme Igneum should restart. The three unfinished items that do matter are Igneum's own open rows (random item derivation, external cryptanalysis, the epoch-length and FPGA-overlay measurement) and they are already ranked in `asic-resistance-history.md` 4.3.
## 3. Group C: merged mining and multi-algo
### 3.1 The rows
| # | Programme | When, by whom | What it bought (numbers) | The attacks and the costs | Left undone |
|---|---|---|---|---|---|
| 1 | Namecoin AuxPoW | Block 19,200, Oct 2011 (vinced; Mike Hearn's outline) | Bitcoin's hashrate for free: about 95 percent of Bitcoin on 12 Jan 2020, about 69 percent (732 EH/s) in Sep 2026; nine pools find blocks (AntPool 34.78 percent, F2Pool 19.99, ViaBTC 19.69, 14-day window to 20 Nov 2025) | One pool (F2Pool) above 50 percent of Namecoin for most of late 2014 to 2016 (approximate; Judmayer et al.: pools "operated at the edge of, and even beyond, the security guarantees" of Nakamoto consensus); the spec's nonce-clash flaw is documented and a replacement BIP never came | Independence: the child's rules are signalled by the parent's pools; Foundry, the largest Bitcoin pool, does not merge-mine it; the name market never grew |
| 2 | Dogecoin on Litecoin | Hard fork at block 371,337, Sep 2014, after Charlie Lee's Apr 2014 proposal; Dogecoin's own words: "our hashrate has been on a decline" | Hashrate up over 1,500 percent in Sep 2014; DOGE and LTC hashrates correlate at 0.95; about 90 percent of DOGE hashrate from Litecoin pools by 2019; DOGE's share of pool revenue "has long surpassed" Litecoin's (F2Pool data, 7 Apr 2026) | A pool above 50 percent of Litecoin is above 50 percent of Dogecoin by construction | A miner base of its own; any say in the parent's rules |
| 3 | Myriadcoin and Verge multi-algo | Myriad 23 Feb 2014 (five algos, per-algo floating difficulty, 20 percent of blocks each); Verge (five algos) | Hardware diversity | Verge, Apr 2018: timestamps spoofed about an hour back on the Scrypt lane, per-lane difficulty collapsed, blocks seconds apart, 250,000 to about 20 M XVG (reports conflict); 22 May 2018: Scrypt and Lyra2re both at near-zero difficulty, about 25 blocks a minute, 35 M XVG (about USD 1.8 M); the hard fork between them did not remove the bug; a 560,000-block reorg in Feb 2021 (headline only) | Five lanes made the surface five times wider; each lane is cheaper to rent than the whole |
| 4 | DigiByte MultiShield, Odocrypt | DigiShield Feb 2014 (block 67,200), MultiAlgo Sep 2014 (145,000), MultiShield Dec 2014 (400,000), Odocrypt Jul 2019 (9,112,320): per-block retarget on all five lanes from a 10-block average, clamps 16 percent down and 8 percent up; Odocrypt rewrites itself every ten days for FPGAs | DigiShield was adopted by Dogecoin (1.6, Mar 2014) and Zcash (v3 variant, approximate); the "93 percent on one algo and 51 percent on the other four" claim is a model, not a measurement | 28 Jun 2026: a dropped validation rule on the Groestl lane let about 1,356 blocks (about 351,000 DGB) be mined, no double spend | A lane with little hashrate still mints one block in five; the ten-day rewrite assumes FPGA owners re-flash and does nothing against a party with many FPGAs |
| 5 | Elastos, RSK | Elastos with Bitmain 28 Aug 2018 (AntPool, BTC.com); RSK since Jan 2018 (approximate) | Elastos "over 50 percent" of Bitcoin's work (13 Mar 2024); RSK 62.46 percent (Q1 2024), 54.58 (Q3), 56.40 (Q4 2024, AntPool 38.6, ViaBTC 24.3, F2Pool 16.9); Foundry joined | RSK's Armadillo (RSKIP110): detects forks up to about 448 blocks when the attacker has under 9 percent of Bitcoin; "cannot stop a miner creating a blockchain from a past point"; the PowPeg is a federation with HSMs | The attacker rents or bribes three pools, not hardware; Armadillo alerts, it does not finalise; usage stayed small so fees stayed small |
| 6 | The paper | Judmayer, Zamyatin, Stifter, Voyiatzis, Weippl, "Merged Mining: Curse or Cure?", eprint 2017/791 | One line: merge-mined chains concentrate in fewer pools than the parent, with single pools above 50 percent for months in Namecoin, Huntercoin and Myriad (approximate for the per-coin detail) | | |
### 3.2 Verdict: does Igneum want any of it
No, with four reasons. Igneum's ruling is already "no reliance on another chain"; the question left is whether an Igneum-side auxiliary chain or an "algo slot" has value, and it does not.
| Option | What it would buy | Why not | Hours |
|---|---|---|---|
| Igneum as a merge-mined child of another chain | Borrowed hashrate | Ruled out (CLAUDE.md: no other chain in consensus); and the rows show the child inherits the parent's pool concentration and loses its say in rules | 0 |
| Igneum as a parent for other chains | Nothing for Igneum; a coinbase commitment slot for others | The hash is a new program every hour, so a child cannot verify Igneum work without Igneum's program pipeline, VDF seed and dataset; the vote key per operator would not carry to the child; the only cost is a header field nobody asked for | 0 until asked |
| An algo slot (a second hash lane) | Hardware diversity | Myriad, Verge and DigiByte show each lane is a separate difficulty controller and a separate rentable surface; Igneum's 30-day vote weight is counted in blue blocks of ONE work unit, so a second lane splits the weight table and the DAA; GHOSTDAG's k is derived from one block rate on one hash | 0 |
| A share sidechain merge-mined through the coinbase | A pool without an operator | This is the one merged-mining shape with value, and it belongs to section 5 (it is how Monero P2Pool works) | see 5.3 |
## 4. Group D: GPU-friendly finality attempts
The one axis asked: can a renter buy or break finality in a day? Igneum's rule for comparison (CLAUDE.md, finality rule v2): vote weight = blue blocks per vote key over a flat 30-day window, lock at 2/3 of all 30-day weight, so 10 days of 100 percent hashrate reach 1/3 of weight and 20 days reach 2/3; 51 percent never reaches 2/3 while honest miners stay.
### 4.1 The rows
| # | Programme | Attempted | Finished | Left undone | Renter buys finality in a day? |
|---|---|---|---|---|---|
| 1 | Decred hybrid | Feb 2016: tickets vote on every block, 3 of 5 called tickets must sign; 40,960 ticket pool, 28-day average wait | A PoS veto on every block, stakeholder-voted forks, a treasury; stake locked rose from 50 percent (Dec 2019) to 64 percent (Dec 2022) while hashrate fell about 6x; DCP-0011 (BLAKE3 and ASERT) and DCP-0012 (PoW to 1 percent of subsidy) active at block 794,368 (Aug 2023) because PoW was "used to maliciously manipulate Decred markets" | No finality gadget; PoW is a 1 percent stipend | No for reorgs (needs about half the live ticket pool, roughly 30 percent of DCR bought over 28-day cycles, approximate); yes for withholding and censorship, since the hash layer is thin |
| 2 | Horizen delayed-block penalty | After the 2 Jun 2018 51 percent attack (over USD 500,000, 36 fake blocks): a block n late owes about n(n-1)/2 extra blocks (approximate formula); shipped in ZEN 2.0.16, late 2018 | A reorg tax on hidden chains | Partition safety: the smaller honest side looks like a hidden chain; Horizen now calls itself an L3 on Base and the PoW mainchain is winding down (approximate) | Yes under 5 blocks and for public mining; a deep secret reorg costs quadratically more. A tax, not finality |
| 3 | Kaspa merge depth and finality depth | MERGE_DEPTH_DURATION 3,600 s, FINALITY_DURATION 43,200 s, PRUNING 108,000 s in rusty-kaspa constants; at 10 BPS since Crescendo (about 5 May 2025): merge depth 36,000 blocks, finality depth 432,000 | Online nodes refuse a reorg deeper than 12 hours; a block cannot merge a side chain older than an hour | Both rules are local and subjective; a node syncing later follows the heaviest DAG; DAGKnight (eprint 2022/1494) is in PRs (1104, 1124, 1132) and not on mainnet | Partly: under 12 hours yes with over 50 percent of an ASIC-only hash (thin rental supply); over 12 hours the attacker splits the network instead |
| 4 | Conflux Tree-Graph, GHAST, PoS votes | GHAST (arXiv 2006.01072): confirmation in O(d log 1/epsilon), about 3d against about 360d for six Bitcoin blocks; adaptive weight switches to a conservative mode under a liveness attack | CIP-43 (Hydra, about 28 Feb 2022): a PoS chain of staked CFX (1,000 CFX per vote) votes on pivot blocks "to protect against 51 percent attacks from PoW" | GHAST alone is probabilistic; the PoS committee is the finality | No for finalised pivot blocks; yes inside the trailing minutes |
| 5 | Ethereum Casper FFG over PoW | EIP-1011 (20 Apr 2018): 1,500 ETH minimum deposit, 50-block epochs, "never revert finalised blocks"; testnet 31 Dec 2017 | Nothing on mainnet; the Berlin Eth2 workshop (Jun 2018) discarded hybrid Casper for the beacon chain | The hybrid itself | Under the design: no for finalised checkpoints (slashing two thirds of deposits), yes inside an epoch. Dropped because "the limited bandwidth of the EVM constrained the size of the validator set", forcing whale-sized deposits |
| 6 | Bitcoin Cash Avalanche pre-consensus | Sechet, Sep 2018 (approximate) | On BCH: nothing. On eCash (XEC): post-consensus finality 14 Sep 2022, staking rewards 15 Nov 2023, pre-consensus 15 Nov 2025 at block 923,347 ("finalise transactions in under 3 seconds"); staked XEC 69.4 B to 242 B in the year to Jul 2024, 350 B+ by Jul 2026; 33 to 94 nodes; 100 M XEC minimum per stake UTXO with 2,016 confirmations | BCH never got it; no slashing (approximate); on quorum loss the chain falls back to heaviest work | No while the quorum holds; yes if the attacker knocks the about 94 Avalanche nodes offline |
| 7 | Ethereum Classic MESS | ECIP-1100, active at block 11,380,000 (Oct 2020) after three Aug 2020 reorgs (3,594, 4,446 and 7,278 blocks; 807,000 and 465,444 ETC double spent): a capped polynomial, up to 31x the local chain's difficulty for a segment older than about 7 hours | No deep reorg on ETC after Oct 2020 (approximate) | Deactivated by ECIP-1110 at block 19,250,000 (Spiral, Jan 2024) because "the costs now outweigh the risks"; Core-Geth v1.13.0 (15 Sep 2026) re-enabled it with 96 unreviewed commits, miners rolled back the same day, PR 53 (merged 6 Oct 2026) restored the deactivation | With MESS on: no for reorgs older than 7 h, yes for short ones, and an eclipse strands a victim. Off today: yes, plain PoW |
| 8 | Zcash trailing finality layer, Crosslink | ECC's TFL book (2023, Wilcox and Hopwood); Shielded Labs builds zebra-crosslink, "a proposed upgrade"; BFT PoS finalises a trailing prefix, PoW continues if BFT stalls | An incentivised feature net; milestone 4 of 5 in early 2026 (search summaries) | Mainnet: nothing by 7 Oct 2026 | Today: yes (plain Equihash, rentable, approximate). Under Crosslink: no for finalised blocks, yes inside the trailing window |
| 9 | Nervos CKB | NC-Max (eprint 2020/1101): two-step confirmation, 3.0 to 6.6 times shorter latency; Eaglesong "ASIC neutral", first chip four months after launch | NC-Max runs since launch | No finality layer; no hybrid plan | Yes in principle; ASIC-only supply is thin |
| 10 | Dash ChainLocks, Syscoin, Komodo | Dash DIP-0008 since block 1,088,640 (Jun 2019): an LLMQ of 300 to 400 masternodes signs the first block seen, 240 signatures lock it; Syscoin copied it over Bitcoin merged mining (4.2.0, block 1,004,200, 30 Apr 2021); Komodo notarises to Bitcoin then Litecoin every 10 to 25 minutes through 64 elected notaries | Finality in about one block (Dash) | A second validator set bought with coins (1,000 DASH per masternode, approximate) or elected (Komodo's 64) | No for locked blocks |
### 4.2 The comparison on the one axis
Every finality on a PoW chain that holds in practice is a second validator set paid in coins: Decred tickets, Dash and Syscoin masternodes, eCash stake, Conflux PoS, Komodo notaries, Casper FFG's 1,500 ETH deposits. Every rule that only reweights work (Horizen's penalty, MESS, Kaspa's 12-hour depth) is subjective and partition-sensitive, and two of the three have been switched off or are winding down.
Igneum is the only design in the table whose second set is the miners themselves, weighted by past blocks, with no coins staked. On the one axis:
| Attacker | Decred | Kaspa | MESS (on) | eCash | Igneum |
|---|---|---|---|---|---|
| Rents 100 percent of hashrate for one day | Withholds, cannot reorg | Reorgs up to 12 h | Reorgs up to about 7 h | Nothing while the quorum holds | Reorders inside the 90-second window (horizon 1, finding 3), nothing past a certificate; has 1/30 of a window's weight at the end of the day, needs 2/3 |
| Rents 100 percent for 20 days | Same | Splits the network | Same as above | Same | Reaches 2/3 of weight only if every honest miner has left; with honest miners staying, 51 percent never reaches 2/3 |
| Buys coins | Buys tickets over 28-day cycles | n/a | n/a | Buys stake | Nothing; weight is not for sale |
What is unfinished in Igneum's own finality is Igneum's, not the industry's: the signed LEAVE item (0.3.16) after the 6 October pause (42.7 percent of the frozen voter table left in three minutes and the pause held a window), the 10-percent-per-hour removal rule, weight-gated deep fork choice and vote-or-burn (horizon 1, findings 2 and 3). The one lesson this group adds: every subjective reweighting rule was eventually turned off by its own chain (MESS twice), so the "no hidden-block n^2 penalty" removal in Igneum's rule v2 was the right side of the history.
## 5. Group E: decentralised pools
### 5.1 The rows
| # | Programme | When, by whom | Design | What it achieved (numbers) | Why it stalled or died | Left undone |
|---|---|---|---|---|---|---|
| 1 | Bitcoin P2Pool | Forrest Voight, 2011 | A share chain with a 30-second share period; window = shares worth 3 blocks of work or 8,640 shares (72 hours), whichever is smaller; the generation transaction pays the window; 0.5 percent to the finder, no operator | 350 GH/s in Apr 2012 (about 2 to 3 percent of Bitcoin, approximate); 1.4 TH/s by Jul 2013; today 915 TH/s on 14 payout addresses (about 0.0001 percent of about 950 EH/s, my division); last commit 19 Sep 2018 | Variance for small miners (a small miner rarely lands a share in the window), dust (one output per miner per block), a 20x faster chain so stales are "common and expected", a 2012 orphan flaw, a Python 2 node on a full bitcoind | Payout aggregation, per-miner vardiff inside the chain, a maintained node (c2pool's C++ rewrite says "v37 is design-stage, do not run in production") |
| 2 | Monero P2Pool | SChernykh, Aug 2021 | A sidechain merge-mined with Monero: 10-second blocks, PPLNS up to 2,160 blocks (6 hours), uncles at 20 percent less, payouts in the Monero coinbase, 0 percent fee, about 0.00027 XMR minimum, every miner runs monerod; three chains (main, mini, nano since v4.7, 30 May 2025); Tari merge mining since the 12 Oct 2024 fork | Today: main 441 MH/s and 561 miners, mini 25.3 MH/s and 1,997, nano 4.8 MH/s and 962; 471 MH/s and 3,520 miners in all, 7.7 percent of 6.13 GH/s (my division); against SupportXMR at 2.35 GH/s (38 percent) and HashVault at 672 MH/s (11 percent); the Monero GUI bundles it | A local node is mandatory; below about 15 MH/s of pool hashrate "not all shares will result in payouts"; three chains fragment the hashrate; share has fallen from double digits (approximate) to 7.7 percent | A light mode; cross-chain vardiff; payout smoothing for mini and nano miners |
| 3 | Stratum V2 | Braiins (Moravec, Capek) with Matt Corallo, 2019, from Corallo's BetterHash draft (12 Mar 2018, never past specification) | Binary, Noise-encrypted; Mining, Job Declaration (renamed from Job Negotiation) and Template Distribution sub-protocols; the SRI translation proxy | SRI v1.0.0 tag 23 May 2023, v1.12.0 17 Sep 2025; native V2 pools: Braiins (JD "since about 2020"), DEMAND (public Nov 2025), ckpool (31 Jul 2026); firmware: Braiins OS, Bitaxe ESP-Miner v2.14.0 (Jun 2026), Auradine; stock Antminer and WhatsMiner are V1 only; the first known Job Declaration block is 955,318 on 25 Jun 2026 (DMND, GoMining's template); seven pools holding about 75 percent of hashrate joined the working group on 7 May 2026 "still in testing" | No primary number for SV2 hashrate; the two V2-native pools mined 753 and 1 of 52,297 blocks in the last year, so under 2 percent on SV2 at all and far under 0.1 percent on JD (approximate conclusion) | Stock firmware, JD at any top-five pool, Windows template building ("not yet supported"), a payout scheme that rewards miner-built templates, any measurement of adoption |
| 4 | Braiins Pool | Slush Pool, Nov 2010; the first anti-hopping score (Rosenfeld 2011, section 3.1) | FPPS "0 percent fees with Braiins OS", 2 percent otherwise; on-chain or Lightning payouts | 13.91 EH/s, 177,359 workers, 13,112 users today; 753 of 52,297 blocks (1.44 percent) in the last year | The oldest pool and the SV2 author holds 1.4 percent | SV2 adoption did not become hashrate |
| 5 | Ocean | Luke Dashjr, 28 Nov 2023, USD 6.2 M seed led by Jack Dorsey | TIDES: a share log eight times the difficulty deep, each share rewarded about eight times, 99.9665 percent chance of at least once, paid in the coinbase itself; DATUM (29 Sep 2024): the miner runs a gateway and a full node and builds its own template, 50 percent fee discount (2 percent, 1 percent with DATUM) | First block's coinbase came from a test server and paid nobody (4 Dec 2023 post-mortem); today 28.97 EH/s, 2,522 users, 1,553 blocks of which 1,316 DATUM (85 percent, my division), 1,073 of 52,297 blocks (2.05 percent) in the last year; Tether committed hashrate Apr 2025 | The template fight: Bitcoin Knots filtered inscriptions and Samourai transactions at launch; Dashjr resigned 29 Aug 2026 after the "mining divide" | A single operator still runs TIDES accounting, share verification and the generation transaction; non-DATUM miners get the pool's policy |
| 6 | DEMAND | Guru Protocol Ltd (company 15235937), Alejandro De La Torre; launched Mar 2025 on the SRI, public Nov 2025 | "The world's first Stratum V2 mining pool"; SLICE pays subsidy by hashrate and fees "by the value you built"; Rootstock merge mining | 1 block in 19 months | Scale | SLICE at size |
| 7 | Kaspa pools | Today: 334.9 PH/s; F2Pool 98.14 PH/s (29.3 percent), HumPool 92.95 (27.8), ViaBTC 37.89 (11.3), K1Pool 16.74 (5.0), WhalePool 13.67 (4.1); top two hold 57 percent | All PPLNS or PPS+ with 0.5 to 4 percent fees | No non-custodial or P2Pool-style pool; solo bridges only (K1Pool Solo, Kaspa-Pool SOLO, HeroMiners SOLO); no pool page explains which DAG blocks pay (approximate: blue blocks in the mergeset, red blocks earn nothing) | n/a | A decentralised pool on a DAG chain has never been built |
| 8 | SmartPool | Luu, Velner, Teutsch, Saxena, eprint 2017/019, USENIX Security 2017 | Shares in batches ("1 transaction can claim 1 million shares") in an augmented Merkle tree; the contract samples k random paths; a caught cheater is paid nothing | ETC first ("over 30 blocks"), Ethereum closed beta Jun 2017; 105 blocks across both, peak 30 GH/s from 2 miners (about 0.05 percent of Ethereum, approximate); cost 0.6 percent of block rewards in transaction fees | Gas prices rose about ten-fold in 2017 and the claim cost passed the fee it was meant to beat; the beta never opened; the team founded Kyber; PoS removed the target (all approximate: smartpool.io is dead) | Any successor with hashrate; the opposite approach (Autolykos v1's non-outsourceable puzzles) was bypassed with collateralised contracts (eprint 2020/044) and removed |
| 9 | Non-custodial on GPU chains, 2024 to 2026 | Ravencoin: 2Miners 292.67 GH/s with "51 percent of recent blocks", Hiveon 621 GH/s, no P2Pool; Ergo: 2Miners 303.14 of 491.76 GH/s (61.6 percent), no P2Pool; SoloPool.org sells solo mining at 1.5 to 2 percent "no pool wallet, no balances" | | Outside Monero every "non-custodial" offer is solo with a stratum bridge, not pooled variance reduction | | |
Share verification cost, from the sources: a Scrypt proxypool spends "around 50 percent of the server's CPU time" checking shares; RandomX light mode on an i9-9900K verifies 1,160 H/s on 16 threads, so a core checks about 70 shares a second (fast mode about 700); Bitcoin SHA256d is microseconds per share (approximate, 10^5 to 10^6 per core). Igneum's pool v0 checks every share on the CPU warp verifier at 1.35 ms isolated and 2.1 ms under load, 480 to 740 per core (`pool.md` section 5), which is RandomX-fast-mode class, 1,000x a SHA256 share.
The payout pattern: FPPS won on Bitcoin because large pools carry variance and sell certainty (Foundry about 30 percent, AntPool about 19, ViaBTC 14, F2Pool 10, d-central 2026); every non-custodial design (P2Pool, Eligius CPPSRB, TIDES, SLICE) is PPLNS-shaped because a coinbase cannot pay a debt. That is the structural reason non-custodial pools stay small, and it is the reason Igneum's pool is PPLNS.
### 5.2 What Igneum's pool lacks against the best of these
Igneum's pool v0 (`docs/plans/pool.md`, spec 09): newline JSON over plain TCP, mode A templates, every share CPU-verified, PPLNS over 2 blocks of weight, 1 percent fee, payouts by EIP-1559 transfer from the pool's coinbase key after blue confirmation, `state.json` every 15 s, the member's vote key in every header it hashes, the pool holds no key, the member checks seeds, class and era against its own node.
| Axis | Best in the field | Igneum v0 | The gap |
|---|---|---|---|
| Operator trust for payout | Monero P2Pool and TIDES pay in the coinbase itself; nobody holds a balance | The operator holds the 80 percent in its coinbase address and pays by transfer at most 16 per round; a crash loses up to 15 s of shares; a dishonest operator can misaccount or withhold | The whole of the trust. Mode C (declared templates) and vote carriage are designed, not built; neither removes the operator from payout |
| Operator trust for template and vote | DATUM and SV2 Job Declaration let the miner build the template; neither touches governance | The member's vote key rides in every header (no Stratum pool does this); mode C is designed, not built | Transaction choice is the pool's in mode A; the vote is already the member's |
| Variance | P2Pool main: 6-hour window, 561 miners; Ocean: a window 8 difficulties deep | PPLNS over 2 blocks of weight at 1 block a second: a 2-second window of work. Each share is 2^-s of a block, so a 100 MH/s card at one share per 10 s is paid on every block it has a share in | The window is short because blocks are frequent; variance is a block-time question, not a pool question, and v0 has no number for the income variance of a 100 MH/s member at devnet scale |
| Share verification | Full recompute everywhere; sampling at high difficulty (spec 9.8 item 5, allowed above shift 8, not built) | 1.35 to 2.1 ms per share, one core per 480 to 740 shares a second, no sampling | One template fetch per member per second is the real limit: 1,000 members is 1,000 `getBlockTemplate` calls a second and 10 MB/s (pool.md section 3) |
| Transport | SV2 Noise encryption, binary framing | Plain TCP, `binding` sent empty, against spec 9.3's TLS 1.3 | Q67 (polish 3.6): 8 hours |
| Stats and alerts | 2miners charts, offline alerts, luck | 15-minute samples not persisted, no `/metrics`, no payout history on the page, luck defined inverted | Q68 to Q73: about 17 hours |
| Finality | No pool in the field has a finality concept | Pays on blueness, says nothing during a pause | Q73: 1 hour |
### 5.3 "Shares as first-class protocol objects, no operator": already in Igneum, partly
| Piece | In Igneum already | Where | What is new |
|---|---|---|---|
| Governance weight follows the hasher, not the pool | Yes: the vote key per operator in the header (spec 9.6), pool concentration is not vote concentration | spec 2.2 fork point a5, spec 9.6 | Nothing; this is further than SV2 or DATUM went |
| An operator-less payout by weight | Yes for the 20 percent: the proving share is paid by sortition by weight from consensus data, no operator | CLAUDE.md, `executor.rs` (pool.md "The 20%") | Nothing for provers |
| A share the chain can see | No: a share is a pool message, verified by the pool, paid by the pool | spec 9.8 | This is the new thing |
The finished form is Monero P2Pool's, not SmartPool's. SmartPool's on-chain claims died on gas at Ethereum's share rate; at Igneum's 1.35 ms per share verification, a contract that samples k paths per million-share claim would still need the zkEVM to re-derive the program's warp unit per sampled share, which is the one cost the design keeps off the chain. A share sidechain merge-mined through the coinbase extra data is the shape that works: Igneum's coinbase already carries the member's key reveal and the pool's address (pool.md section 2), so the commitment slot exists.
| Finish | What it is | Hours (agent) | Gate |
|---|---|---|---|
| A P2Pool-style share sidechain in the pool crate | Shares form a 10-second chain committed in the coinbase extra data; the window's payout is the block's own coinbase split (the execution layer already credits by rule from consensus data for the 20 percent, so the 80 percent split follows the same path); no balance, no operator key; every member runs a node (the design already assumes one, spec 9.1) | about 40 (sidechain 16, coinbase split in the executor 8, member client 8, Devnet 2 crossing 8) | a 3-node fast-time network pays a window with no operator; an operator that drops every share from one member cannot stop that member's payout |
| Mode C declared templates | The miner builds the block (DATUM, SV2 JD) | 6 (O-9.4 RPC 2, messages 4) | a declared template is paid like any other |
| TLS and the `binding` field | spec 9.3 | 8 (Q67) | a replayed `authorize` on a second connection is refused |
The verdict for the group: finish the share sidechain, because it is the one unfinished thing in the field that Igneum's existing objects (vote key in the header, coinbase extra data, execution-layer credit by rule, a node per member) make cheap, and nobody has built one on a DAG chain.
## 6. Group F: mining app UX and the "one click" promise
### 6.1 The rows
Minutes to first share are approximate unless a source is named; they count from the download to the first accepted share on a fresh machine with a driver installed.
| # | Product | Install to first share (min, approximate) | Custody | Fee | What it did that nobody else has | What it left undone | State 2026 |
|---|---|---|---|---|---|---|---|
| 1 | NiceHash (2014; QuickMiner 2020, approximate) | 5 to 10 | NiceHash wallet, BTC only; 2.5 M users (infobox) | Seller 2 percent, buyer 3 percent (approximate); BTC deposits at or above 0.00005 BTC free, Lightning free above 0.0000001 | A hashpower marketplace: the miner never picks a coin | Custody: 6 Dec 2017 spear-phishing hack, about 4,700 BTC (USD 64 M), Lazarus indicted 17 Feb 2021; repayment completed Dec 2020 (approximate); no node, no wallet of the user's own | Alive |
| 2 | HiveOS (2017) | 20 to 40 (flash an image on a second machine or drive, make a web account) | Hiveon pool pays the user's wallet | 2 workers free (3 days of stats); USD 0.50 per card per month to USD 3.00 at 6 or more cards; ASIC USD 2 or free with Hiveon firmware; 10 to 50 percent off at 50 to 1,000 workers | Farm-scale remote management, charts over hours, Telegram and Discord alerts, per-GPU clocks | A second machine or a flash drive; a web account; no local-only mode, no wallet, no node | Alive |
| 3 | Minerstat, Awesome Miner | 15 to 30 | User's pool and wallet | minerstat free to 2 rigs, about USD 1.46 per rig per month on larger plans (approximate); Awesome Miner free to 2 miners, paid from about USD 4 per month (approximate) | Awesome Miner: "up to 200,000 ASIC and 25,000 GPU miners" from one Windows console | Management only; no node, no wallet, no pool | Alive |
| 4 | Salad (2018) | 5 | Salad Balance, redeemable for PayPal, gift cards, games | Not published | Gaming-PC "earn while idle"; 450,000+ GPUs since 2018; 16,000+ daily active GPUs in 190+ countries today | Mining itself: the site no longer mentions crypto; SaladCloud sells GPU-hours from USD 0.015; the user's take rate is not disclosed; payout in gift cards for years | Pivoted to a compute marketplace |
| 5 | Honeyminer (2018) | 3 to 5 | Honeyminer balance, paid in BTC | 8 percent for one GPU, 2.5 percent for two or more (approximate) | The first "download, sign in, earn" miner with no settings | Everything else; the site refuses connections on 7 Oct 2026 | Dead (about 2020 to 2021, approximate) |
| 6 | Cudo Miner (2017) | 5 to 10 | Cudo balance | 1.5 to 3 percent by tier (approximate) | Profit switching on Windows, macOS, Linux | The pivot to Cudo Compute (cloud GPU); docs host unresolvable on 7 Oct 2026 | Pivoted |
| 7 | Kryptex | 5 ("Download, Launch, Earn"; first payout 1 to 8 hours) | Kryptex balance; withdraw BTC, USDT, ETH, USDC, LTC, BNB, TRX, Volet, Amazon gift cards; 0.00025 BTC minimum | "A small pool fee", unstated | "153,000 GPU and ASIC miners", "10 million+ downloads"; the pool: BTC 4,945 miners at 6.63 EH/s, XMR 37,576 miners at 1.08 GH/s; PPS+ | A balance, not a wallet | Alive |
| 8 | unMineable | 5 to 10 | unMineable balance, paid in 80+ assets | 1 percent, 0.75 with a referral code (approximate) | Mine any algorithm, be paid in any coin | A balance; conversion risk; no node | Alive |
| 9 | Bitcoin Core "generate" (2009 to 2016) | 0 (one setting) | The user's own wallet, in the node | None | Node, wallet and miner in one process, the only time it has shipped at scale | Removed in 0.13 (2016) once GPUs and chips made it pointless | Dead |
| 10 | Monero GUI mining | 0 after sync (Advanced, Mining, Start mining; thread count; local node required) | The user's wallet | None | A wallet with the daemon's CPU miner, and P2Pool bundled and updated per release (nano sidechain 26 Aug 2023, P2Pool 4.18.1 on 6 Oct 2024); the nearest shipped "node plus wallet plus miner" | The GPU (RandomX is CPU work); no tuning, no alerts; the sync wait | Alive |
| 11 | Kaspa community miners, the big three | 5 to 15 (a command line, a pool, an address) | The pool's | lolMiner 0.75 percent kHeavyHash, 1.0 Karlsen, 0.7 Ethash, 1.5 Autolykos (v1.96a); BzMiner 1 percent most algorithms, 0.5 ETC, 2 on Pearl and Quantus (v100.45, Windows, Linux, macOS arm64, Docker); GMiner 1 percent kHeavyHash, 2 Ethash and KawPoW, 5 Cortex, "charged continuously"; T-Rex 1 percent (2 on Octopus and Autolykos), 730 open issues, no release date shown; NBMiner 1 to 3 percent, last release 42.3 on 2 Sep 2022 | The per-GPU accepted, rejected, invalid and fault line; kernel speed | No node, no wallet, no tuning against a goal, no signed updates; two of the big three stopped in 2022 (approximate for T-Rex) | lolMiner, BzMiner, GMiner alive; T-Rex and NBMiner stale |
Nobody in the table ships a miner that is also a verifying node and a wallet with a GPU worker: Bitcoin Core did it for CPUs in 2009 and removed it in 2016; the Monero GUI does it for CPUs with P2Pool bundled; every GPU miner is a kernel plus a pool address, and every "one click" app is a custodial balance.
### 6.2 Ember against the field
Ember's state is from `polish.md` 3.1 and 3.10: a Rust engine runs `igneumd` and one GPU worker per card, serves a tokenised local dashboard, Welcome, Cards, Address, the one-time key sheet, Start mining; Ember Tune measured 37 to 41 percent more hashes per watt on PC 1; signed, hash-checked, rolled-back updates with a safe-moment rule; no dev fee in pool mode, a 1-in-100 template solo; pool mode is design only (pool.md section 7).
| Axis | The field's best | Ember today | Past or behind |
|---|---|---|---|
| Node, wallet and miner in one process, GPU | Nobody (Monero GUI for CPU) | Yes: `igneumd`, the worker, the key and the address in one app | Past |
| Custody | Direct-to-wallet only at P2Pool and HiveOS; every one-click app holds a balance | The coinbase pays the user's own address; the vote key never leaves the machine | Past |
| Governance | Nobody | The vote key in every header the card hashes | Past |
| Updates | Unsigned zips (the kernel miners); NiceHash and HiveOS auto-update inside an account | Ed25519-signed manifests, sha256, staged, rolled back after 90 unhealthy seconds, a safe-moment rule | Past |
| Tuning | HiveOS per-GPU clocks by hand; Nanominer's watchdog | A goal with the money consequence on screen, hill climb, 37 to 41 percent per watt | Past |
| Fee | 0.5 to 3 percent dev fees; 1 to 8 percent custodial takes | 1 percent template dev fee solo, 0 in pool mode | Past |
| Install to first share | NiceHash, Honeyminer, Kryptex: about 5 minutes with one interstitial | Windows: SmartScreen interstitial, per-user install, a firewall UAC prompt 20 to 50 s in; Mac: an ad hoc signature that macOS 15 refuses without Privacy and Security, Open Anyway (Q3, Q14, Q15); the Windows installer pipeline is dead on GitHub billing (Q80) | Behind: three prompts against one, and no Windows build until Q80 |
| Earnings | NiceHash's fiat per day on the main screen | "£0.00 earned" first; mined IGN never shown (Q18) | Behind, 2 hours |
| History and alerts | HiveOS hours of charts and Telegram alerts | A 10-minute strip; no outbound alert (Q16) | Behind, 4 hours plus an alert hook |
| Per-card faults | lolMiner's status line | "N blocks" per card; `mismatched=` and `faults=` never reach the row (Q13) | Behind, 2 hours |
| Remote view | HiveOS, NiceHash Rig Manager | None for the owner (the console is the operator's) | Behind; not ranked here |
| Pool mode | Every miner | Design only | Behind; the share sidechain of 5.3 is the finish |
| Finality on the surface | Nobody | Nothing during a pause (Q2) | Behind, 3 hours, and nobody else has the concept |
The honest line: Ember is the first app to ship the thing the table says nobody shipped (node, wallet, GPU miner, own key, signed updates, no custody), and it loses to a 2018 Honeyminer on the sixty seconds between download and first share. The first-run fixes are one Developer ID and one Authenticode certificate (Q3, a the project lead decision) plus the Q80 installer builder; the rest of the behind rows are 11 hours.
## 7. Verdict table
| Group | Unfinished item | Who could finish it | Igneum has it | Hours on Igneum | Recommend |
|---|---|---|---|---|---|
| A | Energy that produces proofs of real state, paid from issuance (Aleo's 2019 promise) | A chain with a prover network and no validator set | Yes once the proof is verified in consensus (`proving_consensus_verify_daa`, 0.3.16, off by default) | 0 beyond the activation decision | Already done; activate |
| A | Pay per verified unit of proving at a market price (PoVW) | Boundless, Succinct, Igneum | Yes (pgas metering, 90/10 external jobs) | 0 | Already done |
| A | Useful work verified cheaper than done AND sampleable AND wanted | Nobody in 13 years | No, and the bound says why (0.08 percent useful at 100 GH/s) | 0.5 (the ledger row beside F13, new-pow.md rank 8) | Skip |
| A | Stored data as the work (Filecoin, Chia) without filler | Lane 8's scheme C | Partly (class v5 candidate, judged) | per new-pow.md rank 1 (16) | Not this lane's call; already ranked |
| B | A tweak that lands before the chip (RandomX v2 merged, unscheduled; ProgPoW dead on governance) | A chain whose parameters move without a vote | Yes (era draws every 6 months, families by height, the class ladder) | 0 | Already done |
| B | The random item derivation and external cryptanalysis of the mixer | Igneum | No | per asic-history 4.3 additions 2 and 3; the spend (USD 80,000 to 160,000) is a decision owed | Finish, through the existing ranking |
| B | The FPGA overlay measurement and the epoch-length reserve | Igneum | Partly (reserve designed on `ca2-epoch`) | per asic-history addition 5 | Finish, through the existing ranking |
| B | Tensor-core PoW measured against a chip | Igneum did it (scheme B) | Yes, retired to reserve R8 with the two-output correction | 1 (new-pow.md rank 5) | Already done |
| C | A merged-mining BIP that replaces the 2011 spec; any child chain with a say in its parent | Namecoin, RSK | n/a (ruled out) | 0 | Skip |
| C | An algo slot or an Igneum-side auxiliary chain | Nobody should | No | 0 | Skip, with the reasons in 3.2 |
| D | Finality on PoW without a coin-bought validator set | Zcash Crosslink (not shipped), Kaspa DAGKnight (PRs) | Yes: miner-only 30-day weight, 20 days at 100 percent hashrate for 2/3 | 0 beyond Igneum's own open rows (LEAVE item, 10 percent rule, weight-gated deep fork choice, vote-or-burn: 0.3.16 and horizon 1) | Already done; finish the own rows |
| D | A subjective reweighting rule that survives its own chain (Horizen, MESS) | Nobody | Removed on purpose (no hidden-block n^2 penalty) | 0 | Skip |
| E | A pool with no operator on a DAG chain | Nobody has; Monero P2Pool is the finished form on a chain | Partly (vote key in the header, the 20 percent paid by sortition, coinbase extra data) | about 40 (section 5.3) | Finish |
| E | Miner-built templates (DATUM, SV2 JD: one block in 52,297) | Igneum's mode C | Designed, not built | 6 | Finish after the sidechain |
| E | Encrypted member transport | SV2 Noise | No (plain TCP, Q67) | 8 | Finish |
| E | A pool-as-contract with sampled share verification (SmartPool) | Nobody since 2017 | No | 0 | Skip (1.35 ms per share makes it worse than it was for Ethereum) |
| F | Node, wallet and GPU miner in one app, own key, signed updates | Nobody; Ember | Yes | 0 | Already done |
| F | Sixty seconds from download to first share | Honeyminer did it in 2018 | No (three prompts, no Windows build) | 6 plus certificates (Q3); 0 or 4 (Q80) | Finish; the certificates are the project lead's |
| F | Earnings in IGN, per-card faults, an hour of history, a finality notice | HiveOS, lolMiner | No (Q18, Q13, Q16, Q2) | 11 | Finish |
| F | Payout in something a gamer can spend (Salad's gift cards) | Salad | No, and the chain says "nothing is bought or sold on devnet" | 0 | Skip until there is a market |
## 8. Three headline findings for the coordinator
1. Every proof-of-useful-work programme that passed both tests (cheap verify, sampleable) did so by making the work useless, and the one exception, Filecoin, ran at 29 to 36 percent utilisation and lost 55 percent of its raw byte power in the year to 14 Sep 2026; Igneum's split already finishes Aleo's 2019 promise, and the only unfinished line (a majority prover pool earning 11,636 IGN an hour at 51 percent) closes when `proving_consensus_verify_daa` is switched on.
2. No pool without an operator exists on any chain but Monero (P2Pool at 7.7 percent, 3,520 miners, 0 percent fee; Ocean at 2.05 percent of blocks with 85 percent of them from DATUM; Stratum V2 job declaration at 1 block in 52,297), and Igneum already holds the three objects that make one cheap (the vote key in the header, the 20 percent paid by sortition, the coinbase extra data), so a share sidechain is about 40 agent hours and would be the first on a DAG chain.
3. Every finality on a PoW chain that held in practice is a second validator set bought with coins (Decred 64 percent of supply staked, eCash 350 B XEC, Dash 1,000 DASH per masternode), and every rule that only reweights work has been switched off by its own chain (MESS twice, Horizen winding down, Kaspa's 12-hour depth subjective); Igneum's work-weighted set needs 20 days of 100 percent hashrate to reach 2/3, so no renter buys it in a day, and the unfinished items are Igneum's own (the LEAVE item and the 10 percent rule), not the industry's.
## 9. Sources
All accessed 7 October 2026 unless stated. Lane notes with the full per-item citations sit in the scratchpad under `mission-unfinished/` (A-notes, B-notes, CD-notes, E-notes, F-notes).
Group A
- https://en.wikipedia.org/wiki/Primecoin ; https://www.johndcook.com/blog/2026/01/10/primecoin-primality-test/ ; https://github.com/primecoin/primecoin/wiki/Primecoin-Reaches-13-primes-Milestone ; https://primecoin.io/ ; https://chainz.cryptoid.info/xpm/ ; https://www.coingecko.com/en/coins/primecoin ; https://bitinfocharts.com/primecoin/
- https://github.com/gridcoin-community/Gridcoin-Wiki/wiki/zArchive~Proof-of-Research ; https://gridcoin.us/assets/docs/scraper-summary.pdf ; https://gridcoin.us/guides/whitelist.htm ; https://github.com/gridcoin-community/Gridcoin-Research/releases/tag/5.5.0.0
- https://curecoin.net/knowledge-base/folding-for-curecoin/how-do-i-start-folding-for-curecoin-quick/ ; https://curecoin.net/news/curecoin-team-reaches-1-trillion-ppd-on-foldinghome/ ; https://curecoin.net/curecoin-roadmap/ ; https://tokenmarket.net/blockchain/counterparty/assets/foldingcoin/
- https://eprint.iacr.org/2020/190 ; https://aleo.org/post/aleo-mainnet-faq/ ; https://docs.aleo.org/participate/run-a-node/prover ; https://github.com/ProvableHQ/ARCs/discussions/97 ; https://provable.com/blog/introducing-arc-0046 ; https://aleo.org/post/announcing-snarkos-v4.0.0/ ; https://messari.io/report/state-of-aleo-q2-2025 (search excerpt; direct fetch 429) ; https://followin.io/en/feed/11596817
- https://eprint.iacr.org/2021/1379 ; https://eprint.iacr.org/2025/2091 ; https://eprint.iacr.org/2017/203 ; https://eprint.iacr.org/2018/559
- https://filecoin.io/blog/posts/a-guide-to-filecoin-storage-mining ; https://lotus.filecoin.io/storage-providers/get-started/hardware-requirements/ ; https://lotus.filecoin.io/storage-providers/operate/benchmarks/ ; https://filecointldr.io/article/key-trends-and-takeaways-from-filecoin-q1-2025 ; https://www.kucoin.com/news/flash/filecoin-q3-2025-report-capacity-drops-10-network-utilization-rises-to-36 ; https://thetradersspread.com/crypto/filecoin-rose-24-percent-ahead-of-75-percent-supply-cut ; https://github.com/filecoin-project/FIPs/discussions/1009 ; https://filecoin.io/blog/posts/introducing-proof-of-data-possession-pdp-verifiable-hot-storage-on-filecoin/
- https://www.chia.net/2022/03/19/chia-mainnet-year-one/ ; https://www.chia.net/2021/05/24/chia-and-ssd-endurance/ ; https://www.chia.net/2021/08/03/chia-and-ssd-endurance-big-progress-less-waste/ ; https://www.chia.net/2023/01/21/plotting-chias-future/ ; https://www.chia.net/2026/02/27/changes-coming-to-3-0/ ; https://lowendbox.com/blog/the-crypto-that-ate-all-the-hard-drives-whatever-happened-to-chia/ ; https://xch.today/2026/02/09/top-10-chia-predictions-for-2026/ ; https://en.wikipedia.org/wiki/Chia_Network
- https://ownyourmind.ai/projects/flux/ ; https://runonflux.com/ ; https://messari.io/report/state-of-akash-q1-2026-final (search excerpt) ; https://akash.network/blog/akash-network-q1-2026-report/
- https://github.com/dynexcoin/Dynex ; https://www.coingecko.com/en/coins/dynex ; https://www.coinlore.com/coin/dynex/news
- https://qubic.org/blog-detail/qubic-s-useful-proof-of-work-the-future-of-ai-compute ; https://qubic.org/blog-detail/the-next-evolution-of-useful-proof-of-work-(upow) ; https://www.halborn.com/blog/post/explained-the-monero-51-percent-attack-august-2025 ; https://www.theblock.co/post/366535/monero-faces-chain-reorganization-fears-after-qubic-says-it-controls-51-of-hashrate ; https://cointelegraph.com/news/monero-qubic-selfish-mining-51-percent-attack ; https://www.bitget.com/news/detail/12560604967511 ; https://wublock.substack.com/p/monero-hit-by-a-51-hashrate-attack
- https://arxiv.org/html/2507.02951v1 ; https://www.theblock.co/news/web3/2026-03-05-dcg-yuma-bittensor-report-392351 ; https://abittensorjourney.com/p/navigating-bittensor-september-2026 ; https://beincrypto.com/bittensor-subnets-reach-ath-in-may/
- https://arxiv.org/abs/2502.19405 ; https://www.gensyn.ai/research/verde-verification-system-in-production ; https://arxiv.org/abs/2405.00295 ; https://blockeden.xyz/blog/2026/04/01/ambient-ai-l1-proof-of-logits-pow-blockchain-decentralized-inference/ ; https://inferencelabs.com/ ; https://arxiv.org/abs/2603.19025 ; https://arxiv.org/pdf/2512.20176 ; https://blockeden.xyz/blog/2026/01/14/boundless-risc-zero-decentralized-proof-market-zk/ ; https://blog.succinct.xyz/succinct-2025-recap/
- https://arxiv.org/abs/2209.03865 ; https://eprint.iacr.org/2025/1814 ; https://arxiv.org/abs/2606.06700 ; https://arxiv.org/abs/2606.04819 ; https://arxiv.org/abs/2510.09729
Group B
- https://eips.ethereum.org/EIPS/eip-969 ; https://eips.ethereum.org/EIPS/eip-1057 ; https://ethereum.org/en/developers/docs/consensus-mechanisms/pow/mining-algorithms/ethash/ ; https://github.com/eth-classic/etchash ; https://2miners.com/blog/how-to-mine-ethereum-and-ethereum-classic-on-4gb-gpus/
- https://leastauthority.com/static/publications/LeastAuthority-ProgPow-Algorithm-Final-Audit-Report.pdf ; https://github.com/ethcatherders/progpow-audit (PDF text not extractable) ; https://github.com/kik/progpow-exploit ; https://github.com/ethereum/EIPs/issues/2640 ; https://hudsonjameson.com/posts/2020-03-02-progpow-the-ethereum-community-speaks/ ; https://cointelegraph.com/news/the-history-of-the-bitter-debate-over-ethereums-progpow ; https://www.theblock.co/linked/57061/ethereum-community-members-submit-dissenting-progpow-petition ; https://www.coindesk.com/tech/2020/03/05/ethereums-progpow-debate-is-about-much-more-than-mining ; https://www.coindesk.com/tech/2020/03/06/ethereums-progpow-call-features-frustration-but-little-progress ; https://github.com/Souptacular/linzhi ; https://linzhi.io/docs/LWP15-Posts-Against-ProgPoW-05092019.pdf ; https://cryptoslate.com/progpow-authors-steps-down-core-scientific-ethereum/ ; https://ecips.ethereumclassic.org/ECIPs/ecip-1070 ; https://2miners.com/blog/kawpow-new-ravencoin-mining-algorithm/ ; https://en.wikipedia.org/wiki/Firo_(cryptocurrency) ; https://www.qu.ai/blog/quai-network-mainnet-launching-january-29th
- https://github.com/tevador/RandomX ; https://github.com/tevador/RandomX/pull/265 ; https://github.com/tevador/RandomX/pull/317 ; https://github.com/monero-project/monero/pull/10038 ; https://github.com/monero-project/research-lab/issues/136 ; https://xmrig.com/docs/algorithms ; https://github.com/xmrig/xmrig-cuda/issues/67 ; https://www.asicminervalue.com/miners/bitmain/antminer-x5 ; https://www.asicminervalue.com/miners/bitmain/antminer-x9 ; https://millionminer.com/news/monero-mining-guide-2026-antminer-x5-x9-pinecone-r1x-randomx (reseller, unverified) ; https://www.coindesk.com/business/2025/08/12/monero-s-51-attack-problem-inside-qubic-s-controversial-network-takeover
- https://arxiv.org/abs/1911.05193 ; https://kaspa-lens.com/kaspa-wiki/kaspa-technology-and-features/kheavyhash-proof-of-work-algorithm/ ; https://kaspa-lens.com/kaspa-wiki/getting-started-with-kaspa/mining-kaspa/ ; https://www.asicminervalue.com/miners/iceriver/ks0 ; https://github.com/karlsen-network/karlsend ; https://github.com/spectre-project/rusty-spectre ; https://github.com/Pyrinpyi/pyipad
- https://docs.ergoplatform.com/mining/autolykos/ ; https://www.ergoforum.org/t/autolykos-v-2-details/480 ; https://github.com/ergoplatform/eips/blob/master/eip-0027.md ; https://eprint.iacr.org/2020/044 ; https://x.com/RedPandaMining/status/1697408861014196711 ; https://cryptoage.com/en/3019-osprey-e300-fpga-miner-for-kaspa-cryptocurrency.html
- https://github.com/mimblewimble/grin/blob/master/doc/pow/pow.md ; https://docs.grin.mw/about-grin/proof-of-work/ ; https://forum.grin.mw/t/grin-v5-0-0-network-upgrade-hard-fork-4-january-2021/7895 ; https://2miners.com/blog/grin-version-4-hard-fork-what-will-change-and-how-to-get-ready/ ; https://forum.grin.mw/t/grn1-cancellation-announcement/5624 ; https://voskcointalk.com/t/new-grin-miner-coming-out/6373 ; https://www.asicminervalue.com/miners/innosilicon/g32-500 ; https://www.asicminervalue.com/miners/ipollo/g1 ; https://2cryptocalc.com/cuckatoo32-algorithm ; https://github.com/tromp/cuckoo
- https://coinbureau.com/mining/battle-against-asics-antminer-z9-zcash ; https://github.com/ZcashFoundation/zfnd/blob/master/_posts/blog/2018-05-08-statement-on-asics.md ; https://raw.githubusercontent.com/ZcashFoundation/zfnd/master/_posts/blog/2018-06-07-asic-equihash-study.md ; https://raw.githubusercontent.com/ZcashFoundation/zfnd/master/_posts/blog/2018-07-03-governance-results.md ; https://forum.zcashcommunity.com/t/will-zcash-fork-to-be-asic-resistant/30829 ; https://crypto.news/zcash-doubles-efforts-on-investigating-asic-resistance/ ; https://github.com/BeamMW/beam/wiki/BEAM-Mining ; https://www.minerupdate.com/news/trending-news/beam-hard-fork-executes-to-deter-asic-miners ; https://u.today/privacy-coin-beam-introduces-new-proof-of-work-algorithm ; https://cryptoage.com/en/2095-beam-cryptocurrency-hard-fork-new-beamhash3-mining-algorithm.html ; https://en.wikipedia.org/wiki/Bitcoin_Gold ; https://www.tweaktown.com/news/62048/bitcoin-gold-hit-51-attack-up-18-million-gone/index.html
- https://github.com/Conflux-Chain/CIPs/blob/master/CIPs/cip-102.md ; https://forum.conflux.fun/t/cip-102-change-pow-mining-algorithm/16068 ; https://f2pool.io/mining/guides/how-to-mine-conflux/ ; https://www.asicminervalue.com/coins/conflux-cfx
- https://docs.alephium.org/frequently-asked-questions/ ; https://docs.alephium.org/mining/ ; https://www.asicminervalue.com/miners/goldshell/al-box ; https://www.asicminervalue.com/miners/bitmain/antminer-al1
- https://eprint.iacr.org/2025/685 ; https://ethresear.ch/search.json?q=tensor%20core%20proof%20of%20work
- https://arxiv.org/abs/1905.08792 ; https://medium.com/@dave_46855/altered-silicon-x16r-mining-on-the-xilinx-fpga-dbc290c56909 (search excerpt; fetch 403) ; https://forum.zcashcommunity.com/t/equihash-mining-in-fpga/31054 ; https://cryptoage.com/en/3195-all-hashaltcoin-fpgas-get-support-for-the-kheavyhash-algorithm.html
Group C
- https://github.com/namecoin/wiki/blob/master/Merged-Mining.mediawiki ; https://www.namecoin.org/docs/faq/ ; https://en.bitcoin.it/wiki/Merged_mining_specification ; https://metrics.namecoin.org/namecoin/period-timestamps-14-days/pool/charts/latest.txt ; https://forum.namecoin.org/viewtopic.php?f=6&t=2421 (search excerpt; fetch 500) ; https://cryptorank.io/news/feed/7620f-while-bitcoins-hashrate-remains-sky-high-merge-mined-crypto-asset-networks-benefit (search excerpt; fetch 403) ; https://eprint.iacr.org/2017/791
- https://www.coindesk.com/markets/2014/08/04/dogecoin-to-allow-litecoin-merge-mining-in-network-security-bid ; https://www.binance.com/en/research/analysis/merged-mining (search excerpt) ; https://www.bitdeer.com/learn/dogecoin-the-logic-of-auxpow-and-stable-profits ; https://www.mexc.com/learn/article/dogecoin-mining-2025-how-doge-is-mined-merge-mining-and-miner-economics/1
- https://myriadteam.github.io/ ; https://www.pxdojo.net/2017/04/myriadcoin-untold-story-of-invincible.html ; https://thenextweb.com/news/hackers-verge-blockchain-steal-1-7m ; https://bitcoinist.com/verge-xvg-hacked-35-million-xvg-tokens-reportedly-generated-hacker/ ; https://en.wikipedia.org/wiki/Verge_(cryptocurrency) ; https://cryptonary.com/verge-suffers-reorg-attack-200-days-of-transactions-wiped-away/ (headline only)
- https://solofury.com/blog/digibyte-dgb-explained-for-miners/ ; https://www.gemini.com/cryptopedia/digibyte-mining-digibyte-coin-dgb-coin
- https://cryptobriefing.com/elastos-bitmain-merged-mining/ ; https://blog.elastos.net/news/ela-queen-of-bitcoin/ ; https://rootstock.io/blog/merged-mining-insights-report-q1-2024/ ; https://rootstock.io/blog/rootstock-x-bitcoin-merged-mining-insights-report-q4-2024/ ; https://rootstock.io/blog/the-security-architecture-of-rootstock-and-the-principle-of-defense/ ; https://github.com/rsksmart/RSKIPs/blob/master/IPs/RSKIP110.md
Group D
- https://docs.decred.org/proof-of-stake/overview/ ; https://docs.decred.org/research/hybrid-design/ ; https://github.com/decred/dcps/blob/master/dcp-0011/dcp-0011.mediawiki ; https://github.com/decred/dcps/blob/master/dcp-0012/dcp-0012.mediawiki ; https://xaur.github.io/decred-news/journal/201912 ; https://xaur.github.io/decred-news/journal/202012 ; https://xaur.github.io/decred-news/journal/202112 ; https://xaur.github.io/decred-news/journal/202212
- https://www.coindesk.com/tech/2018/10/10/a-solution-to-cryptos-51-attack-fine-miners-before-it-happens ; https://blog.horizen.io/horizens-51-attack-solution/ (search excerpt; fetch 403) ; https://www.horizen.io/ ; https://docs.horizen.io/
- https://raw.githubusercontent.com/kaspanet/rusty-kaspa/master/consensus/core/src/config/constants.rs ; https://raw.githubusercontent.com/kaspanet/rusty-kaspa/master/consensus/core/src/config/bps.rs ; https://raw.githubusercontent.com/kaspanet/rusty-kaspa/master/consensus/core/src/config/params.rs ; https://eprint.iacr.org/2022/1494 ; https://github.com/kaspanet/rusty-kaspa/pull/1104 (search excerpt)
- https://arxiv.org/abs/2006.01072 ; https://www.usenix.org/conference/atc20/presentation/li-chenxing ; https://doc.confluxnetwork.org/docs/general/hardforks/v2.0 ; https://doc.confluxnetwork.org/docs/general/conflux-basics/consensus-mechanisms/proof-of-stake/pos_overview
- https://arxiv.org/abs/1710.09437 ; https://eips.ethereum.org/EIPS/eip-1011 ; https://eth2book.info/latest/part2/consensus/overview/ ; https://hackmd.io/@tvanepps/Beacon-Book ; https://ethresear.ch/t/convenience-link-to-casper-sharding-chain-v2-1-spec/2332 ; https://github.com/ethereum/pm/blob/master/AllCoreDevs-EL-Meetings/Meeting%2041.md
- https://e.cash/blog/ecash-day-2024-celebrating-three-years-of-ecash-xec ; https://e.cash/blog/eCash-day-2026 ; https://e.cash/blog/preconsensus-launch ; https://e.cash/blog/staking-guide ; https://e.cash/blog/avalanche-faq
- https://meowsbits.github.io/51-percent-docs/ ; https://ecips.ethereumclassic.org/ECIPs/ecip-1100 ; https://ecips.ethereumclassic.org/ECIPs/ecip-1110 ; https://www.kucoin.com/news/flash/etc-miners-revert-to-argos-after-core-geth-v1-13-0-controversy ; https://github.com/ethereumclassic/core-geth/issues/44 ; https://github.com/ethereumclassic/core-geth/pull/53
- https://electric-coin-company.github.io/tfl-book/design/crosslink.html ; https://shieldedlabs.net/crosslink/ ; https://zechub.substack.com/p/arborist-call-88-r-and-d-updates
- https://eprint.iacr.org/2020/1101 ; https://www.nervos.org/mining (search excerpt; fetch 429)
- https://docs.dash.org/projects/core/en/21.0.0/docs/guide/dash-features-chainlocks.html ; https://syscoincore.org/en/releases/4.2.0/ ; https://komodoplatform.com/en/docs/start-here/core-technology-discussions/delayed-proof-of-work/
Group E
- https://en.bitcoin.it/wiki/P2Pool ; https://github.com/p2pool/p2pool ; https://github.com/p2pool/p2pool/commits/master ; https://github.com/treib-holdings/p2pool.org/issues/1 ; https://github.com/frstrtr/c2pool
- https://github.com/SChernykh/p2pool ; https://github.com/SChernykh/p2pool/blob/master/README.md ; https://github.com/SChernykh/p2pool/releases ; https://monero.observer/schernykh-releases-p2pool-v4.7-support-nano-sidechain/ ; https://www.getmonero.org/resources/moneropedia/p2pool.html ; https://data.miningpoolstats.stream/data/monero.js?t=1791359405 ; https://xmrchain.net/api/networkinfo ; https://supportxmr.com/api/pool/stats ; https://api.hashvault.pro/v3/monero/pool/stats ; https://p2pool.observer/ (502 on every try)
- https://github.com/TheBlueMatt/bips/blob/betterhash/bip-XXXX.mediawiki ; https://github.com/stratum-mining/sv2-spec ; https://github.com/stratum-mining/stratum/releases ; https://stratumprotocol.org/ ; https://braiins.com/stratum-v2 ; https://braiins.com/pool ; https://d-central.tech/data/stratum-protocol-matrix/ ; https://d-central.tech/bitcoin-mining-pool-comparison-2026/ ; https://www.spark.money/research/bitcoin-stratum-v2-mining-decentralization ; https://cryptobriefing.com/demand-pool-first-stratum-v2-block/ ; https://www.tftc.io/stratum-v2-job-declaration-first-block-dmnd-gomining/ ; https://www.dmnd.work/ ; https://mempool.space/api/v1/mining/pools/1w ; https://mempool.space/api/v1/mining/pools/1y
- https://ocean.xyz/docs/tides ; https://ocean.xyz/docs/datum ; https://ocean.xyz/dashboard ; https://bitcoinmagazine.com/technical/an-ocean-launch-post-mortem ; https://crypto.news/bitcoin-mining-divide-pushes-luke-dashjr-out-of-ocean/
- https://data.miningpoolstats.stream/data/kaspa.js?t=1791359405 ; https://2miners.com/kas-mining-pool ; https://woolypooly.com/en/coin/kas ; https://f2pool.io/mining/guides/how-to-mine-kaspa/ ; https://kaspa.herominers.com/?lang=en ; https://solopool.org/
- https://eprint.iacr.org/2017/019 ; https://blog.acolyer.org/2017/09/07/smartpool-practical-decentralized-mining/ ; https://eprint.iacr.org/2020/044
- https://miningpoolstats.net/coins/ravencoin/ ; https://2miners.com/erg-mining-pool
- https://github.com/dogestreet/proxypool ; https://arxiv.org/pdf/1112.4980 ; https://arxiv.org/pdf/1402.1718 ; https://arxiv.org/abs/1411.7099 ; https://eprint.iacr.org/2015/155 ; https://en.bitcoin.it/wiki/Eligius
Group F
- https://en.wikipedia.org/wiki/NiceHash ; https://www.nicehash.com/support/general-help/nicehash-service/fees-and-pricing (deposit fees only; the seller and buyer fee pages returned 404)
- https://hiveon.com/pricing/
- https://www.awesomeminer.com/ ; https://minerstat.com/ (no pricing on either page fetched)
- https://salad.com/ ; https://support.salad.com/article/213-how-much-can-i-earn-with-salad (no take rate published)
- https://www.kryptex.com/ ; https://pool.kryptex.com/
- https://unmineable.com/
- https://www.getmonero.org/resources/user-guides/solo_mine_GUI.html ; https://github.com/monero-project/monero-gui/releases
- https://github.com/Lolliedieb/lolMiner-releases ; https://github.com/bzminer/bzminer ; https://github.com/develsoftware/GMinerRelease ; https://github.com/trexminer/T-Rex ; https://github.com/NebuTech/NBMiner
- Unreachable on 7 Oct 2026: honeyminer.com (connection refused), docs.cudominer.com (no DNS), cudominer.com (429), web.archive.org (blocked for this tool)
Igneum documents cited
- `CLAUDE.md` (the design paragraph, finality rule v2, the fee lines, the 6 October 2026 rules)
- `docs/analysis/asic-resistance-history.md` (rows 3, 17 to 25, 30; lessons 5 to 9; sections 4.1 to 4.3)
- `docs/plans/pool.md` sections 2, 3, 5, 7; `docs/spec/09-pool-protocol.md` sections 9.1 to 9.8
- Scratch inputs: `mission-inputs/horizon/new-pow.md` sections 3.1, 3.3, 6, 7; `mission-inputs/horizon/frontier.md` sections 0, 3.10, 3.11; `mission-inputs/horizon-2026-10.md` section 1; `mission-inputs/horizon/polish.md` sections 3.1, 3.6, 3.10

View file

@ -12,3 +12,6 @@
docs/analysis/horizon/polish.md
# the CI failure classification of 6 October 2026 (an operations document: run ids, step names, the fixes)
docs/analysis/ci-failures-2026-10-06.md
# 7 October 2026: the last research round (the mission lanes and the closed list): internal research written for the
# owner, quoting his words and the operations record; the public spec mirror carries none of it
docs/analysis/mission