From 537438854564f476a50b16937ad9098f12e5d79d Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 15:37:02 +0000 Subject: [PATCH 1/6] Litepaper to the Igneum 2.0 reference: positioning line, the proof architecture as separate decisions, the three boundaries, NVIDIA proves and AMD and Apple mine, the pool vote-key pin, proof enforcement in consensus as the D5 prerequisite, class v5 state coupling under evaluation (D3), no rotation-as-defence, no 0.x history, no testnet, no devnet number; /claims and /randomx rebuilt from it Removes pins X3 and X31 (the testnet sentences). F10 kept, marked as today's behaviour beside the 2.0 pin. The metamask page's anchor follows the renamed devnet terms heading. Co-Authored-By: Claude Fable 5.1 --- site/claims.html | 8 +- site/litepaper.html | 195 +++++++++++++++++++++++--------------------- site/metamask.html | 2 +- site/randomx.html | 6 +- 4 files changed, 110 insertions(+), 101 deletions(-) diff --git a/site/claims.html b/site/claims.html index 1265730e6..db1d49806 100644 --- a/site/claims.html +++ b/site/claims.html @@ -251,7 +251,7 @@

Here are the limits, stated before anyone else states them.

Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything. Found an error, or a criticism this document does not answer? Email hello@igneum.network, or open an issue on the public specification repository: git.igneum.network/igneum-network/spec/issues. Post reaches Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre.

diff --git a/site/litepaper.html b/site/litepaper.html index af5e0e685..2d4b7577f 100644 --- a/site/litepaper.html +++ b/site/litepaper.html @@ -4,7 +4,7 @@ Igneum Litepaper: how the chain works - + @@ -299,14 +299,14 @@ body.all .pager{display:none}
-
The litepaper · version 0.2
+
The litepaper · Igneum 2.0

Mined by GPUs.
Proven by fire.

-
A proof-of-work chain whose miners also prove every block, run Ethereum's apps, and are protected from specialised chips by a program that changes every hour.
+
A GPU-secured network for Ethereum-compatible applications and verifiable computation.
- Published 3 October 2026 · updated 7 October 2026 + Published 3 October 2026 · updated 8 October 2026 Coin IGN · cap 4,000,000,000 - Status Devnet 3 live, testnet armed + Status Devnet 3 is the network today Method one founder with AI systems · external review before gate 3 This is not an offer to sell anything
@@ -343,11 +343,11 @@ body.all .pager{display:none}

Abstract

-

Igneum is a proof-of-work blockchain built for graphics cards, where NVIDIA cards also prove every block with zero-knowledge proofs and sell proving to other chains. Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling places the strongest specialised designs assessed against the GPU tier at about 2.3x to 3.3x energy-efficiency advantage a node ahead (2.0x to 2.9x on the GPU's own node), a bracket that is approximate and provisional until the placed gated core rows land. The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment. The chip model: every number labelled measured, modelled or claimed, the harness and the scoring rules beside it.

-

It runs the Ethereum virtual machine, so anything built for Ethereum runs on Igneum unchanged. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two. There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining stays open to anyone with a GPU because the mining program changes every hour, so a chip built for one program is useless for the next, and a chip for the whole program space is a GPU without the graphics parts. No scheduled human release is needed to keep it that way. Writing new code, including an emergency fix to the proof system, is the one thing that takes a person, and it activates only on miner signalling.

+

A GPU-secured network for Ethereum-compatible applications and verifiable computation. Igneum is a proof-of-work chain built for graphics cards. AMD, Apple and NVIDIA cards mine; NVIDIA cards also prove its blocks with zero-knowledge proofs. Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling places the strongest specialised designs assessed against the GPU tier at about 2.3x to 3.3x energy-efficiency advantage a node ahead (2.0x to 2.9x on the GPU's own node), a bracket that is approximate and provisional until the placed gated core rows land. The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment. The chip model: every number labelled measured, modelled or claimed, the harness and the scoring rules beside it.

+

It runs the Ethereum virtual machine through revm, so contracts built for Ethereum deploy with familiar tools; the differences (block context, randomness, two-dimensional fees) are documented. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two (designed targets). There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining is built to stay open to anyone with a GPU. The argument rests on the scoring rule's result against placed adversary designs and on the economics, reported separately as energy advantage, economic advantage and response capability. The hourly program is an optional improvement, not the defence. Writing new code, including an emergency fix to the proof system, is the one thing that takes a person, and it activates only on miner signalling.

-
1 / s
blocks, rising to 10
-
~60 s
to a proof at launch
+
1 / s
blocks, rising to 10 (designed)
+
~60 s
to a proof at launch (designed)
0
premine or stake
100%
to miners and provers
@@ -357,12 +357,12 @@ body.all .pager{display:none}

Precedents, and what Igneum adds

Every piece of Igneum has a precedent somewhere. We know of no chain that combines them. The table names the closest precedent for each piece, what Igneum adds, and how far each piece has got. It will be corrected when shown wrong.

- + - - - - + + + + @@ -396,7 +396,7 @@ body.all .pager{display:none} 1. Mining lotteryA random GPU program picks who makes the next block - New program every hour: a chip wired for one program is useless + A new program every hour; the chip model scores the rest @@ -408,12 +408,12 @@ body.all .pager{display:none} 3. EVM execution Blocks carry transactions only; the proof computes the state - Solidity, wallets and tooling work unchanged + Familiar Solidity, wallets and tooling; differences documented 4. Miners prove the block - Shards proven on consumer GPUs, aggregated into one proof + Shards proven on NVIDIA cards, aggregated into one proof Lands within about a minute at launch, paid from gas @@ -425,34 +425,34 @@ body.all .pager{display:none} External proving jobs - Rollups and bridges pay Igneum - Same GPUs, same proof format + Designed: rollups and bridges buy proofs + Same NVIDIA cards, same proof format winning blockordered blocksstate transitionsaggregated proof
Five layers plus the external proving market. A block flows down the column; outside demand feeds the same miners from the side.
-

Live on Devnet 3, 7 October 2026

-

Devnet 3 (igneum-devnet-3, chain id 4464 since its class v5 floor at DAA 68,400, 4463 from genesis to the floor; the chain’s current state is the release manifest) made its first block at 18:06 UK on 7 October 2026 with every upgrade on from block zero, and locked its first checkpoint at 20:02 UK. The first devnet ran from 3 October 2026 and took each upgrade by height. Coins on Devnet 3 have no value and the chain may be reset. What is on it:

+

Live on the devnet

+

The Igneum 2.0 devnet is the network. Its coins have no value and the chain may be reset. What is on it:

PieceClosest precedentWhat Igneum addsState, 7 Oct 2026
PieceClosest precedentWhat Igneum addsState, 8 Oct 2026
A mining program that regenerates itself, for GPUsRandomX on Monero since 2019, for CPUs, a program per hash; one chip shipped against it, Bitmain’s Antminer X5 (September 2023), a board of RISC-V chips at 1.46x per joule over a desktop CPU, on silicon believed mining privately from about 2021; the X9 was withdrawn in May 2026 with zero units; RandomX v2 was released on 25 March 2026 with its activation pending. ProgPoW, as KAWPOW on Ravencoin since 2020, changes the maths inside a fixed program shape every few blocks on GPUs (approximate)A whole kernel per hour compiled to native code, a daily dataset from a 256 MB cache, a verifiable delay before the seed, era draws from a genesis reserveMeasured: hourly swaps on Apple, NVIDIA and AMD cards on the live devnet, 4 October 2026
The mining card does paid, useful, verifiable workPrimecoin's prime chains in 2013 were not useful. Aleo ran proving as consensus and the fastest prover won (both approximate)Proving kept apart from the lottery; shards assigned by sortition, not by speedImplemented: proving v0 and v1 on Devnet 3 from block zero (7 October 2026), v0 on the first devnet since 5 October 2026. The job market for other chains is Designed
A proof-of-work chain where every block is provenzkEVMs run as rollups on proof-of-stake Ethereum. Conflux has run GPU-mined EVM apps on a DAG since 2020, without proofs (approximate)Proven state on a proof-of-work base layer, produced by the miners themselvesImplemented in part: shards proven and paid on the devnet. The aggregated block proof checked in consensus is Designed
Finality held by miners and not moved by hour-long rentalsDecred votes with stake. Horizen penalises hidden chains. Kaspa limits merge depth (approximate)Vote weight is 30 days of blocks per key. Hashrate that appeared today has no voteImplemented: rule v3 live on Devnet 3 from block zero, first lock 7 October 2026; rule v2 ran the first devnet from its first lock on 4 October 2026. External review is owed at gate 3
A mining program that regenerates itself, for GPUsRandomX on Monero since 2019, for CPUs, a program per hash; one chip shipped against it, Bitmain’s Antminer X5 (September 2023), a board of RISC-V chips at 1.46x per joule over a desktop CPU, on silicon believed mining privately from about 2021; the X9 was withdrawn in May 2026 with zero units; RandomX v2 was released on 25 March 2026 with its activation pending. ProgPoW, as KAWPOW on Ravencoin since 2020, changes the maths inside a fixed program shape every few blocks on GPUs (approximate)A whole kernel per hour compiled to native code, a daily dataset from a 256 MB cache, a verifiable delay before the seed, era draws from a genesis reserveMeasured: hourly program swaps on Apple, NVIDIA and AMD cards, 4 October 2026
The mining card does paid, useful, verifiable workPrimecoin's prime chains in 2013 were not useful. Aleo ran proving as consensus and the fastest prover won (both approximate)Proving kept apart from the lottery; shards assigned by sortition, not by speedImplemented: proving v0 and v1 on the devnet from block zero, on NVIDIA cards. The job market for other chains is Designed
A proof-of-work chain where every block is provenProven-execution EVM chains run as rollups on proof-of-stake Ethereum. Conflux has run GPU-mined EVM apps on a DAG since 2020, without proofs (approximate)Proven state on a proof-of-work base layer, produced by the miners themselvesImplemented in part: shards proven and paid on the devnet. Proof verification enforced in consensus is Open
Finality held by miners and not moved by hour-long rentalsDecred votes with stake. Horizen penalises hidden chains. Kaspa limits merge depth (approximate)Vote weight is 30 days of blocks per key. Hashrate that appeared today has no voteImplemented: rule v3 live on the devnet from block zero. External review is owed at gate 3
100% of emission to the people running the hardwareKaspa's fair launch. Zcash and Decred fund developers from emission (approximate)No fee to any team, foundation or fund in the protocol. The miner software's optional 1% dev fee is the one payment to the project, off with one flagImplemented in consensus: the 80/20 coinbase on the devnet
A chain your browser verifies by itselfLight clients trust a committee, as Ethereum's trust a sync committee (approximate)At launch, one execution proof plus a certificate the client is given. The consensus proof that makes the checkpoint self-verifying is phase twoDesigned. The home page's card verifies a devnet certificate in the browser today, with the voter list taken from a node
- - - - - - - + + + + + + +
LayerStateSince
Mining lotteryClass v4 (sub-version 3) from the first block: the latency-shadow program, a new program every hour on Apple, NVIDIA and AMD cards, compiled ahead, the era VDF armed, the ladder at rung 0block zero, 7 Oct 2026
BlocksOne a second is the target; the live page reads the rate from the observerblock zero, 7 Oct 2026
DifficultyRule v2, a 600-second reference window, from the first block (the first devnet switched to it by height at DAA 33,000 on 4 Oct 2026)block zero, 7 Oct 2026
FinalityRule v3: a checkpoint every 30 s of chain, locked at two thirds of all 30-day weight, the weight table frozen at the last lock during a pause. First lock 20:02 UK, 7 Oct 2026. No coin is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window, and equivocation strips it for 30 daysblock zero, 7 Oct 2026
Provingv0 and v1 from the first block: shards are assigned to miners' keys, proven on their cards, aggregated into segment records and carried in blocks; fees calibratedblock zero, 7 Oct 2026
EmberThe one-click miner, version 0.3.22 on channel devnet-3 (7 Oct 2026); the app window still says Igneum Miner4 Oct 2026, first install
WalletIgneum Wallet 0.1.5 on macOS (0.1.1 first shipped 5 Oct 2026)7 Oct 2026
Mining lotteryClass v4 (sub-version 3) from the first block: the latency-shadow program, a new program every hour on Apple, NVIDIA and AMD cards, compiled ahead, the era VDF armed, the ladder at rung 0block zero
BlocksOne a second is the target; the live page reads the rate from the observerblock zero
DifficultyRule v2, a 600-second reference window, from the first blockblock zero
FinalityRule v3: a checkpoint every 30 s of chain, locked at two thirds of all 30-day weight, the weight table frozen at the last lock during a pause. No coin is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window, and equivocation strips it for 30 daysblock zero
Provingv0 and v1 from the first block: shards are assigned to miners' keys, proven on their NVIDIA cards, aggregated into segment records and carried in blocks; fees calibratedblock zero
EmberThe one-click miner, on the devnet channel4 Oct 2026, first install
WalletIgneum Wallet on macOS5 Oct 2026, first shipped
-

Measured: the 0.3.22 release record (7 October 2026: genesis, first block, the gate lines and the first lock); engineering log, "first hourly program swap on the live devnet", "difficulty rule v2 activated on the live devnet at DAA 33,000", "first finality lock on the live devnet" (4 October 2026, the first devnet). The block rate and the first lock are rows 7 and 10 of the evidence table.

-

Two caveats, stated here before anyone else states them. Consensus does not yet verify a carried proof; it checks the record's statement against native execution and its signature, and the in-consensus verifier switches on when the proven share of blocks reads one. And the devnet is the project's own machines, its rented fleet and a few outside laptops. Nothing here has been reproduced by anyone outside the project yet; the evidence page says so row by row.

+

Source: the facts page carries the network row; the block rate and the lock are rows of the evidence table.

+

Two caveats, stated here before anyone else states them. Consensus does not yet verify a carried proof. Today, under proving v0, every producer verifies off the consensus path, and consensus checks the record's statement against native execution and its signature. Open: proof verification enforced in consensus (verifier_in_consensus, proof_rule_active_from) is the prerequisite of the no-rescue network exercise (Deliverable 5) and of the proving economy being a protocol guarantee. And the devnet is the project's own machines, its rented fleet and a few outside laptops. Nothing here has been reproduced by anyone outside the project yet; the evidence page says so row by row.

-

Mining: a program that never holds still

-

Every GPU chain that promised ASIC resistance shipped a fixed algorithm, and a fixed algorithm gets a chip the moment the prize pays for one. Igneum does not have a fixed algorithm.

+

Mining: commodity GPUs, scored against a chip

+

Every GPU chain that promised ASIC resistance shipped a fixed algorithm, and a fixed algorithm gets a chip the moment the prize pays for one. Igneum does not assume its algorithm keeps chips away. It assumes a specialised chip exists, seeks profit and stays compatible, and it states how far ahead that chip gets.

Each hour the chain derives a seed from a locked checkpoint one epoch back, passes it through a ten-minute verifiable delay so no miner can see which program a seed implies before choosing whether to publish a block, and feeds it to a deterministic generator. The generator emits a random integer program built from what graphics cards are uniquely good at: wide parallel integer maths, shuffles between the 32 lanes of a warp, and dependent reads spread over a multi-gigabyte dataset that changes daily, so the program waits on memory latency, not on maths or bandwidth. Measured: an RTX 5090 hashes at 95 GB/s of useful 4-byte loads against 1,638 GB/s of sequential writes (engineering log, the RTX 5090 entries). The memory footprint and instruction count are fixed and only the maths sequence is random, so no hour favours one vendor's cards and nobody gains by grinding the seed. Miners compile the program once per hour. Anyone running a node, a wallet or an exchange checks a hash on an ordinary CPU in under ten milliseconds by simulating one warp, so nobody needs a GPU except to mine. Measured: 0.61 ms per warp on one Apple M5 Max core for class v2 and 2.1 ms for class v3 (the mixer at x8, 5 October 2026, one core at load average 5.5, worst cold unit 2.15 ms), 3.4x the class v2 verifier; the 10 ms gate leaves 4.8x (4.6x on the worst cold unit); a 2019-class laptop core is not yet measured.

The hash is a lottery, not a general-purpose cryptographic hash. It has to be unpredictable per nonce, free of any shortcut cheaper than honest evaluation, and free of bias a miner can exploit. It does not need preimage or collision resistance. Open: no analysis of the lottery properties exists yet. It is the first job of the external review in phase 1, and until then the hash is a design claim backed by the measurements below.

@@ -462,23 +462,23 @@ body.all .pager{display:none} - +
Every hourA new random programNo, the miner compiles whatever arrives
Every dayA new datasetNo
Every six monthsA new instruction mix and memory pattern drawn by the chain from rules fixed at genesis, and a new family of instructions unlocked from a reserve written at genesis, so the program space widens every era. A schedule change against fixed datapaths and human forks, not a surprise: a programmable chip reads every drawn parameter as firmwareNo
ContinuouslyThe dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. A chip is built with fixed memory, so it is on a countdown from the day it ships. Ethereum's growing dataset ran Bitmain's E3 out of memory in 2020 this way, approximate, with nobody doing anythingNo
ContinuouslyThe dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. Each step is scored against the burden it puts on ordinary cards (Deliverable 3); growth is not counted on to retire a chipNo
-

Three ideas carry the chip resistance. The hash rewrites itself. A new program every hour, drawn from the chain. Its memory pattern changes with it. The rules change on a schedule fixed at launch. No release, no vote. These are automatic schedule changes: they defeat a chip wired for one datapath and they need no human fork. Against a chip that stores the dataset every drawn parameter is firmware, and what meets that chip is the latency-shadow work (class v4) and the price per joule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). It waits on memory, not maths. Every hash is a chain of random reads into a table too big for a chip to carry. Measured (8 October 2026; lane D’s family harness at the acceptance rule’s own 2^20 sample over 4,900 drawn eras, and the chained-cache pass’s reading of the night before): every hash’s 128 dependent reads land across the whole dataset and the distinct-index floor holds at 0.995 on every accepted program; about half of epochs carry one load site whose address bit at the era’s stride rotation is biased, which prices about 1.6 percent of a hash’s reads to a chip storing half the dataset and nothing to a chip storing all of it; the next class folds the product’s low bits before the rotation, so no era lands a biased bit on an address bit. The wait is the same physics for everyone. Miners hold the switch. Spare defences are written into the rules, switched off. A miner signal turns one on, at the class-change threshold: miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. No fork.

+

What carries the chip resistance is the scoring rule's result on the placed adversary rows, plus the economics, reported separately in the chip model below. Three properties feed it. Rotation is an option, not the defence. A new program every hour, drawn from the chain, its memory pattern with it, and rules that change on a schedule fixed at launch. These schedule changes defeat a chip wired for one datapath and need no human fork, but against a programmable chip that stores the dataset every drawn parameter is firmware, so the security argument does not rest on them. What meets that chip is the latency-shadow work (class v4) and the price per joule (the chip and economy analysis of 6 October 2026, section 5.4; ledger M32). It waits on memory, not maths. Every hash is a chain of random reads into a table too big for a chip to carry. Measured (8 October 2026; lane D’s family harness at the acceptance rule’s own 2^20 sample over 4,900 drawn eras, and the chained-cache pass’s reading of the night before): every hash’s 128 dependent reads land across the whole dataset and the distinct-index floor holds at 0.995 on every accepted program; about half of epochs carry one load site whose address bit at the era’s stride rotation is biased, which prices about 1.6 percent of a hash’s reads to a chip storing half the dataset and nothing to a chip storing all of it; the next class folds the product’s low bits before the rotation, so no era lands a biased bit on an address bit. The wait is the same physics for everyone. Miners hold the switch. Spare defences are written into the rules, switched off. A miner signal turns one on, at the class-change threshold: miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. No fork.

The work that waits can grow. Class v4 adds a block of latency-shadow arithmetic to every hash, about 100,000 integer operations that run while the memory reads are in flight, so a chip that stores the whole dataset still has to pay for a core. That size sits on a ladder fixed at genesis, six rungs from about 100,000 to about 1,000,000 operations, and it moves one rung at a time only when 90 percent of blue blocks in each of seven consecutive days ask for it; it can never move two rungs inside a week and never past a rung the reference verifier cannot check under 10 ms with its sibling thread busy (measured on the build server, 6 October 2026: the first three rungs pass at 8.8, 8.9 and 9.2 ms, the fourth misses by 0.08 ms on a loaded box and stays out until a quiet re-measurement, the two doublings are out at 12.4 and 15.0 ms). What it buys against a chip is scored under the rule in the chip model below. What it costs, per rung, is measured too: the Apple tier gives up 3 points of rate at the first step and 6 more at the second, the RTX 5090 nothing until the second; so the miners who pay for a step are the ones who take it (ledger M34).

The chip model

Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling places the strongest specialised designs assessed against the GPU tier at about 2.3x to 3.3x energy-efficiency advantage a node ahead (2.0x to 2.9x on the GPU's own node), a bracket that is approximate and provisional until the placed gated core rows land. The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment.

The labels. The bracket is modelled and provisional: its floor is the clock-gated base core and its ceiling the first placed core, which came in 64 percent above synthesis (wires and the clock tree); the honest figure is the placed gated core’s and replaces the bracket when its row lands. The GPU side is measured: an RTX 5080 at its 1,100 MHz core lock, 2.06 microjoules per hash, and an RTX 5090 at its 1,300 MHz lock, 2.33 microjoules per hash, both under class v4, on the project’s own rigs and rented pods, 8 October 2026; the card’s cost of the window is measured too (a rented RTX 5090 and RTX 4090 at stock, 8 October 2026: within 5 percent per load with the liveness chain, no register spill). The chip side is synthesised and claimed: the clock-gated sequencer core with the 64-register window on ASAP7, scaled to N3 on the foundry’s headline factors (k about 0.37 at N3 and 0.51 node for node for the base core, the gated window adding about 0.13 of k against an adversary with a flop register file; the window’s liveness measured at 61 of 64 values necessary, its cost to the card measured under 5 percent); the window’s k is synthesis-derived and not a lower bound, and the multi-family adversary lane’s first core (its state in a macro) reads the window’s defence as close to nothing, a disagreement between two models that the placed rows settle. The chip’s memory is modelled: the GDDR7 board of the chip model. The placed gated figure is expected near 2.6x to 3.1x a node ahead and 2.3x to 2.7x node for node (approximate) and is served when its row lands.

Three statements, kept separate. The baseline is the hash as it stands under the scoring rule; rotation is an optional improvement to that baseline, not the mechanism the claim rests on.

- - - + + +
StatementWhat it saysLabel and date
Energy resistanceThe bracket above: about 2.3x to 3.3x for the strongest specialised design a node ahead of the GPU tier, 2.0x to 2.9x on the GPU’s own node, provisional until the placed gated core row lands; two nodes ahead follows from that row. The honest tier moves to the next node with every GPU generation; a chip must tape out again.modelled on measured cards, 8 October 2026, approximate and provisional; the node column is claimed scaling
Economic resistanceWhether a chip gets built depends on development cost, deployment economics and productive hardware lifetime. The first cut of the profitability surface: the price at which a project pays scales as the project cost over its share of the chain times its discounted life, and moves by under 5 percent with the per-joule edge; a fixed-lane chip under rotation needs 4x the price a programmable one needs. No threshold is the headline: the coexistence model that prices the conditions (docs/analysis/class-v6/coexistence-model.md) is owed and is served when it exists.modelled, first cut, 8 October 2026; conditional until the cut lands
Response capabilityRotation is an optional improvement, not the mechanism. A passed rotation boundary proves the rotation works, not that hardware dies. The schedule: a new program every hour, a parameter era every week, a family epoch every 180 days, an emergency vote when miners call one.measured per boundary, 8 October 2026
Energy resistanceThe bracket above: about 2.3x to 3.3x for the strongest specialised design a node ahead of the GPU tier, 2.0x to 2.9x on the GPU’s own node, provisional until the placed gated core row lands; two nodes ahead follows from that row. The honest tier moves to the next node with every GPU generation; a chip must tape out again. Whole machine per tier (synthesis with the SRAM band and node factors, claimed; placed rows to follow): the complete GDDR7 machine about 1.8x the RTX 5090 at its lock per joule node for node and 2.1x a node ahead; 1.6x and 1.9x the RTX 5080; 2.8x and 3.3x the Ada, Ampere and RX 9070 XT cohort; about 1.5x the Apple tier, reported, never headlined.modelled on measured cards, 8 October 2026, approximate and provisional; the node column is claimed scaling; the per-tier line claimed, 8 October 2026
Economic resistanceWhether a chip gets built depends on development cost, deployment economics and productive hardware lifetime. The first cut of the profitability surface: the price at which a project pays scales as the project cost over its share of the chain times its discounted life, and moves by under 5 percent with the per-joule edge; a fixed-lane chip under rotation needs 4x the price a programmable one needs. No threshold is the headline: the five-year coexistence model (Deliverable 4; its first run is docs/analysis/class-v6/coexistence-model.md, every row modelled) replaces any capex wall: the GDDR7 board passes all six of its success conditions at a one to three year life; an N2 SRAM die fails five once it exists with development sunk, and the only condition holding it is that nobody pays to build it; the larger half of a chip's edge is capital cost per accepted hash, not joules.modelled, the coexistence model's first run, 8 October 2026
Response capabilityRotation is an optional improvement, not the mechanism. A passed rotation boundary proves the rotation works, not that hardware dies. The schedule: a new program every hour, a parameter era every week, a family epoch every 180 days, an emergency vote when miners call one. Rotation costs a chip versatility, not life: the family bank is firmware plus about 43 percent of core cells, and no transition carries an obsolescence credit (modelled).measured per boundary, 8 October 2026; the family-bank cost modelled, 8 October 2026
-

What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). Devnet 3 runs class v4 from its first block (7 October 2026); the first devnet started on class v3 and reaches class v4 by miner signal at a published height. Classes rotate on findings and at least yearly; a class change is a release activated by block height. Class v5 crosses on Devnet 3 by height; class v6 is the design in progress (opened 8 October 2026), with four layers as its spine: per-era draws of the parameters a release now fixes, a dataset whose size tracks the chain state, scheduled family epochs by height, and the acceptance floor generalised to every era’s draw. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet.

-

No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds and the response the rotation makes, and both carry their labels. The precedents, as sourced (nameplate and community tables, about 20 percent either way; every figure with its URL and date in the close): Monero has run on RandomX since November 2019, its rules stable since then and its programs varying per hash; one chip shipped against it, Bitmain’s Antminer X5 (September 2023), 46 months after the fork, at 6.37 J per kH at the wall against a stated CPU measurement, an observed comparison, not a ceiling. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. RandomX v2 was released on 25 March 2026 with its mainnet activation pending. Ethash ran 36 months to a first chip worse than a GPU; the iPollo V2H reads about 14x today. Kaspa ran 21 months to its first chip, at 167x to 725x. The commodity cohort Igneum protects is the discrete-GPU population; the Apple row is reported beside it, never as the headline.

-

The scoring rule and the harness. The edge is the minimum over workloads of the maximum over free adversarial designs of the GPU’s joules per hash over the adversary’s, under four conditions: the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness and hardware accessibility. The rejected designs stand as negative controls with their measured rows: the long program, the select tree, the wide read, the scratchpad. The next programme: the connected-state experiment, the mixed integer and FP32 candidate, the multi-family programmable adversary; rotation is not expected to deliver the missing joule. The scoring rules and every row, section 10. The harness and its readings (measured, 8 October 2026): the acceptance floor at 0.995 refuses nine of nine hot sets (0.9809 to 0.9919) and 2.435 percent of 4,600 drawn programs, 0 of 61 in the era reading (section 14); the attack families F8, F4, F9 and F1 pass, F8 with a residue of 61 of 64 (section 13); the attempts census and the attempt-3 read (section 0).

+

What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). The devnet runs class v4 from its first block. Classes rotate on findings and at least yearly; a class change is a release activated by block height. Class v5 is built to cross by height; its dataset keyed by the chain's own state is under evaluation (Deliverable 3) and is not counted as a defence until justified. Class v6 is the design in progress (opened 8 October 2026), with four layers as its spine: per-era draws of the parameters a release now fixes, a dataset whose size tracks the chain state (under evaluation, Deliverable 3), scheduled family epochs by height, and the acceptance floor generalised to every era’s draw. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet.

+

No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the economics and the response capability, each separately, and each carries its label. The precedents, as sourced (nameplate and community tables, about 20 percent either way; every figure with its URL and date in the close): Monero has run on RandomX since November 2019, its rules stable since then and its programs varying per hash; one chip shipped against it, Bitmain’s Antminer X5 (September 2023), 46 months after the fork, at 6.37 J per kH at the wall against a stated CPU measurement, an observed comparison, not a ceiling. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. RandomX v2 was released on 25 March 2026 with its mainnet activation pending. Ethash ran 36 months to a first chip worse than a GPU; the iPollo V2H reads about 14x today. Kaspa ran 21 months to its first chip, at 167x to 725x. The commodity cohort Igneum protects is the discrete-GPU population; the Apple row is reported beside it, never as the headline.

+

The scoring rule and the harness. The edge is the minimum over workloads of the maximum over free adversarial designs of the GPU’s joules per hash over the adversary’s, under four conditions: the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness and hardware accessibility. The rejected designs stand as negative controls with their measured rows: the long program, the select tree, the wide read, the scratchpad. The two architectural experiments are closed as failures and stay as regression controls: the mixed integer and FP32 branch (measured, 8 October 2026: 15 to 26 percent more card energy per hash against the 10 percent budget) and the connected-state reorganisation (8 October 2026: only the window width reaches the chip). The multi-family programmable adversary (Deliverable 3) is open; rotation is not expected to deliver the missing joule. The scoring rules and every row, section 10. The harness and its readings (measured, 8 October 2026): the acceptance floor at 0.995 refuses nine of nine hot sets (0.9809 to 0.9919) and 2.435 percent of 4,600 drawn programs, 0 of 61 in the era reading (section 14); the attack families F8, F4, F9 and F1 pass, F8 with a residue of 61 of 64 (section 13); the attempts census and the attempt-3 read (section 0).

One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.

@@ -490,27 +490,41 @@ body.all .pager{display:none} Hardware it is built forCPUs. GPUs run it badly on purposeGPUs. Any card, any vendor. Bit-exact on Apple, NVIDIA and AMD, measured Random programPer hash, interpreted in a virtual machinePer hour, compiled to native GPU code. Per hash, the 128 dataset addresses change with the nonce - DatasetAbout 2 GB, the same size since 2019, approximate2 GB, growing (the proposed schedule, fixed at the testnet genesis: 2 GB, doubling at years 4, 12 and 28); a 4 GB card mines about four years, an 8 GB card about twelve, approximate + DatasetAbout 2 GB, the same size since 2019, approximate2 GB, growing (the proposed schedule, fixed at genesis: 2 GB, doubling at years 4, 12 and 28); a 4 GB card mines about four years, an 8 GB card about twelve, approximate Light verification256 MB cache on a CPU, milliseconds256 MB cache on a CPU (512 MB from year 4), one warp under 10 ms, the gate. Measured 2.1 ms on one Apple M5 Max core for class v3 (3.4x class v2's 0.61 ms); a 2019-class core not yet Changes over timeNone. A fixed design, unchanged for seven yearsA new program every hour, its memory pattern with it; era draws and reserved families on a schedule fixed at genesis. Nobody touches it Seed grindingNot applicable, the program comes from the hash inputClosed by a verifiable delay between seed and program - Useful workNone. Hashing onlyEvery NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server (eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026); they sell proofs to other chains. AMD and Apple cards mine, and a prover for them lands when a zkVM ships one + Useful workNone. Hashing onlyNVIDIA cards prove: from 8 GB on the patched server, 12 GB and up beside the miner, 24 GB on the stock server (measured on eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026). Selling proofs to other chains is Designed, not built. AMD and Apple cards mine and do not prove; a prover for them lands when a zkVM ships one Track recordAbout seven years with one shipped chip, Bitmain’s Antminer X5 (September 2023), at 1.46x per joule over a desktop CPU; the one announced beyond it, Bitmain’s Antminer X9, was withdrawn in May 2026 with zero units; RandomX v2 released 25 March 2026, activation pendingZero years. Every number above is measured and logged with the commands that produced it. The specification, reference hash, test vectors and simulators are public now (git.igneum.network/igneum-network/spec). The node, the miner and the wallet follow to the same host as the repository is published -

Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Those are prototype figures, not mining rates. The first prototype dataset was a closed-form function, and a miner could compute items instead of loading them: measured 111x faster that way on the Mac. The 256 MB cache construction replaced it on 3 October 2026. With the cache, computing items on the fly runs 4.8x slower than loading them, measured on the Mac, and the honest rate is unchanged on both vendors. Open: the same shortcut ratio on NVIDIA and on a discrete AMD card, and the time-memory trade-off between the two measured points. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. On 4 October 2026 the live devnet crossed an hourly program change on all three vendors with no pause and no rejected block: a Mac at 26.7 million hashes a second, an RTX 5090 at 123 million and an integrated AMD chip at 2.7 million, every hash doing 128 distinct reads of the memory-hard dataset.

+

Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Those are prototype figures, not mining rates. The first prototype dataset was a closed-form function, and a miner could compute items instead of loading them: measured 111x faster that way on the Mac. The 256 MB cache construction replaced it on 3 October 2026. With the cache, computing items on the fly runs 4.8x slower than loading them, measured on the Mac, and the honest rate is unchanged on both vendors. Open: the same shortcut ratio on NVIDIA and on a discrete AMD card, and the time-memory trade-off between the two measured points. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. On 4 October 2026 a live network crossed an hourly program change on all three vendors with no pause and no rejected block: a Mac at 26.7 million hashes a second, an RTX 5090 at 123 million and an integrated AMD chip at 2.7 million, every hash doing 128 distinct reads of the memory-hard dataset.

Proving: the miners are the provers

-

Every Igneum block is proven with a zero-knowledge proof, and the miners produce it. Proving is a useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not. Wrapped for light clients, a phone checks it in milliseconds; the wrapping cost is a phase two measurement. Measured so far, the certificate half only: the browser verifier on the home page checks a devnet finality certificate, one BLS aggregate signature over 16 keys and 21 header hashes, in 139 to 155 ms cold and 58 to 68 ms warm in a phone-sized tab on a laptop core (5 October 2026). No phone has been measured, and no wrapped block proof exists yet.

+

A GPU-secured network for Ethereum-compatible applications and verifiable computation.

+

The proof architecture

+

Igneum is not an Ethereum L2. Ethereum does not enforce its state or hold its data, so Igneum carries its own consensus security, data availability and cross-chain verification. The architecture is three decisions, kept separate, and one source of extra demand. EVM-compatible execution is what developers build against, through revm. SP1 is the one well-tested proving backend, behind the versioned proving interface; a zkEVM here means the EVM implementation compiled as a program SP1 proves. Igneum's own GPU-mined consensus is where security comes from. External customers are the source of additional proving demand: designed, not built, and out of every revenue assumption.

+
+ + + + + + + +
DecisionChoiceState, 8 Oct 2026
What developers build againstEVM-compatible execution (revm), with a documented set of differences: block context, randomness, two-dimensional feesImplemented on the devnet
How execution is provedSP1, one well-tested backend behind the versioned proving interface; program identities, verifier versions and security parameters pinned in the protocol; a second backend only where justifiedImplemented: proving v0 and v1 on the devnet. The pinning is Designed
Where security comes fromIgneum's own GPU-mined consensus: the lottery, GHOSTDAG ordering and miner-only finalityImplemented on the devnet; external review owed
Additional proving demandExternal customers buying proofs for their own systemsDesigned, not built; out of revenue assumptions
+

Proven execution is not finality. EVM compatibility is not Ethereum security. ZK is not privacy.

+

A proof says the state follows from the ordered blocks; the miners' lock decides which blocks are final. Running Ethereum's bytecode does not bring Ethereum's validators. Published state data is public, and privacy needs its own application or protocol design. None of these choices, by itself, answers specialised mining hardware; the chip model is a separate obligation.

+

Igneum blocks are proven with zero-knowledge proofs, and NVIDIA miners produce them. AMD and Apple cards mine; they do not prove today. Proving is a useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not. Wrapped for light clients, a phone checks it in milliseconds; the wrapping cost is a phase two measurement. Measured so far, the certificate half only: the browser verifier on the home page checks a devnet finality certificate, one BLS aggregate signature over 16 keys and 21 header hashes, in 139 to 155 ms cold and 58 to 68 ms warm in a phone-sized tab on a laptop core (5 October 2026). No phone has been measured, and no wrapped block proof exists yet.

How a block gets proven

-

Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond. Provers run them on consumer cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch. Because the proof computes the state from the ordered sequence, no node accepts a block with a wrong state root. Full nodes also execute every block natively and reject a proof record whose result differs from their own execution, so a forged proof is a light-client problem and never a chain split. Implemented: the native-execution check on every carried proof record, proving v0 on the devnet (specification section 7). The emergency path for a soundness bug in the proof system is a human one: a new proof-system version is written by people and activates only on miner signalling. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.

-

Proving: every NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server. Measured on eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026: the RTX 3060 (12 GB) mines at 23.78 MH/s and proves the v1 shard beside its miner at an 8.9 GB peak in 37.5 s; the RTX 4060 (8 GB) proves it alone at 7.4 GB in 18.4 s; the RTX 4090 (24 GB) proves it on the stock SP1 server in 5.6 s at 17.4 GB. The patched server that fits the smaller cards is not yet in the shipped app. AMD and Apple cards mine. A prover for them lands when a zkVM ships one.

+

Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond. Provers run them on consumer NVIDIA cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch (designed). Because the proof computes the state from the ordered sequence, no node accepts a block with a wrong state root. Full nodes also execute every block natively and reject a proof record whose result differs from their own execution, so a forged proof is a light-client problem and never a chain split. Implemented: the native-execution check on every carried proof record, proving v0 on the devnet (specification section 7). The emergency path for a soundness bug in the proof system is a human one: a new proof-system version is written by people and activates only on miner signalling. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.

+

Proving is NVIDIA's today: from 8 GB on the patched server, 12 GB and up beside the miner, 24 GB on the stock server. Measured on eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026: the RTX 3060 (12 GB) mines at 23.78 MH/s and proves the v1 shard beside its miner at an 8.9 GB peak in 37.5 s; the RTX 4060 (8 GB) proves it alone at 7.4 GB in 18.4 s; the RTX 4090 (24 GB) proves it on the stock SP1 server in 5.6 s at 17.4 GB. The patched server that fits the smaller cards is not yet in the shipped app. AMD and Apple cards mine. A prover for them lands when a zkVM ships one. These rows are the proving stage only: the full pipeline is judged, inputs, proving, aggregation, verification, payment, memory and the mining income forgone, and a fast shard does not settle it.

The proving budget

-

Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Measured on 5 October 2026 (an RTX 5090 under SP1 6.8.1's GPU prover, the shard size the chain adopts from its fee switch, 30,000 proving gas, about 4.7 million prover cycles): one full shard proves in 4.3 seconds and needs 20.4 GB of GPU memory with the card to itself, so a 24 GB card proves full shards and a 12 GB or 16 GB card does not on this prover build, whose floor is 13.9 GB for even an empty shard; mining and proving on one card needs 32 GB today (the prototype-size shard beside the miner peaked at 30.1 GB) and 24 GB once the adopted shard size is live (22.2 GB beside the miner, 13.2 seconds a shard, measured on the 32 GB card; a 24 GB card has not run it yet). The old 12 GB gate on the roadmap was withdrawn on 5 October until a prover build with a smaller floor was measured; on 6 October a patched server proved the same shard at 7.4 to 8.0 GB alone on eleven rented cards from the RTX 3060 to the RTX 5090 (the real-card table), so the gate returns as measured and the patched server is not yet in the shipped app. The first proofs exist: on 4 October 2026 an RTX 5090 proved a small two-transaction block in 1.4 seconds (2.7 seconds compressed), verified in 0.22 and 0.038 seconds, and a laptop CPU proved a three-shard block end to end in 19 minutes. Later that day the same card proved a full shard at the provisional size, 6.75 million prover gas, which executed in 60.8 million cycles: core proof 8.3 seconds, compressed proof 10.9 seconds, verified in 0.040 seconds; a four-shard block took 44.5 seconds of GPU stages end to end. Since 5 October 2026 shards are assigned and proven on the live devnet. The gate asks for a mid-range card, and an RTX 5090 is not one, so the gate stands open. Once the gate is measured, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface, so Igneum can adopt a better proof system when one exists by a miner-signalled release, and runs for ever on the current one if none is adopted.

+

Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Measured on 5 October 2026 (an RTX 5090 under SP1 6.8.1's GPU prover, the shard size the chain adopts from its fee switch, 30,000 proving gas, about 4.7 million prover cycles): one full shard proves in 4.3 seconds and needs 20.4 GB of GPU memory with the card to itself, so a 24 GB card proves full shards and a 12 GB or 16 GB card does not on this prover build, whose floor is 13.9 GB for even an empty shard; mining and proving on one card needs 32 GB today (the prototype-size shard beside the miner peaked at 30.1 GB) and 24 GB once the adopted shard size is live (22.2 GB beside the miner, 13.2 seconds a shard, measured on the 32 GB card; a 24 GB card has not run it yet). The old 12 GB gate on the roadmap was withdrawn on 5 October until a prover build with a smaller floor was measured; on 6 October a patched server proved the same shard at 7.4 to 8.0 GB alone on eleven rented cards from the RTX 3060 to the RTX 5090 (the real-card table), so the gate returns as measured and the patched server is not yet in the shipped app. The first proofs exist: on 4 October 2026 an RTX 5090 proved a small two-transaction block in 1.4 seconds (2.7 seconds compressed), verified in 0.22 and 0.038 seconds, and a laptop CPU proved a three-shard block end to end in 19 minutes. Later that day the same card proved a full shard at the provisional size, 6.75 million prover gas, which executed in 60.8 million cycles: core proof 8.3 seconds, compressed proof 10.9 seconds, verified in 0.040 seconds; a four-shard block took 44.5 seconds of GPU stages end to end. Shards are assigned and proven on the devnet from block zero. The gate asks for a mid-range card, and an RTX 5090 is not one, so the gate stands open. Once the gate is measured, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface. SP1 is the one backend. A replacement is adopted only where justified, by a miner-signalled release, never as an interchangeable second backend, and the chain runs for ever on the current one if none is adopted.

Proving for everyone else

-

The same miners accept proving jobs from other chains. Rollups post a job, a miner wins it, proves it, and is paid. The job market is permissionless and is Designed, not yet built. At launch a job is paid on the customer's own chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum. Settlement in IGN, with 10% of each fee burned, follows when the proof bridge lets Igneum see the payment, in phase two. The Igneum miner client can also bid on other proving networks and take the best price, where a miner chooses to hold their collateral: Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation). The proving market is small today. Igneum does not depend on it. We know of no other proof-of-work chain selling proofs to other chains. Live rows arrive with the public testnet. The public testnet is armed: three seed nodes and the public RPC are up, and it opens on the go word.

+

The job market for other chains is Designed, not built, and stays out of every revenue assumption until it is. The order: Igneum's own execution first; then one external customer's exact workload with repeat paid jobs; further workloads only where the fleet has a demonstrated edge. As designed, a customer posts a job, a miner wins it, proves it, and is paid, and the market is permissionless. At launch a job is paid on the customer's own chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum. Settlement in IGN, with 10% of each fee burned, follows when the proof bridge lets Igneum see the payment, in phase two. The Igneum miner client can also bid on other proving networks and take the best price, where a miner chooses to hold their collateral: Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation). The proving market is small today. Igneum does not depend on it. We know of no proof-of-work chain that sells proofs to other chains.

@@ -520,7 +534,7 @@ body.all .pager{display:none}

Finality

Every 30 seconds of chain a checkpoint forms, deep enough past the tip that the DAG will not reorder it. Every miner with at least 100 blocks in the last 30 days signs it, and the checkpoint locks when signatures representing two thirds of all the mining weight of those 30 days arrive. Once a checkpoint is locked it overrides the heaviest chain, so fresh hashrate cannot reorganise past it. Two thirds of 30-day weight can. In the chain's first 30 days no checkpoint locks at all: the rule waits until the window holds 30 days of history (Implemented, the first-month gate, measured on test networks on 4 and 5 October 2026), so the chain runs on proof of work and its 12-hour finality depth the way every new proof-of-work chain does. On the devnet, whose window is two hours, the first lock came two hours after genesis, at 77.4% of all weight from 17 vote keys (4 October 2026).

The word sustained is the whole defence. Block rewards go to whoever mines, new or old. The right to lock history is earned.
-

A miner's vote weight is simply the blocks it has mined over the trailing 30 days, measured by work, so splitting into many keys buys nothing and joining a pool costs nothing. Hashrate that arrived today holds almost none of it. Even an attacker producing every block on the chain, with honest miners gone, would need ten days of mining in public to hold a third of the weight, and twenty to hold two thirds. An attacker matching the honest network needs twenty days for a third and never reaches two thirds while the honest miners keep mining. Rental is priced by the hour. The only route left is to drive honest miners off the chain and hold two thirds for a month on the public hashrate charts, which is the same limit Bitcoin lives with, with a month's warning attached. Pools carry their hashers' votes, so vote concentration equals pool concentration, and it is public.

+

A miner's vote weight is simply the blocks it has mined over the trailing 30 days, measured by work, so splitting into many keys buys nothing and joining a pool costs nothing. Hashrate that arrived today holds almost none of it. Even an attacker producing every block on the chain, with honest miners gone, would need ten days of mining in public to hold a third of the weight, and twenty to hold two thirds. An attacker matching the honest network needs twenty days for a third and never reaches two thirds while the honest miners keep mining. Rental is priced by the hour. The only route left is to drive honest miners off the chain and hold two thirds for a month on the public hashrate charts, which is the same limit Bitcoin lives with, with a month's warning attached. Pools carry their hashers' votes, so vote concentration equals pool concentration, and it is public (today's behaviour, as built). The pin replaces it: vote keys stay with the miner at protocol level: the member's retained voting key is committed into its work, payment aggregation is separate and verifiable, and pool identity substitution is resisted (a pin of Igneum 2.0, pools and participation; not yet shipped).

Two further rules close the gaps. A lock needs two thirds of all 30-day weight, so finality pauses whenever less than two thirds of that weight is connected and signing, until it returns or ages out of the window, up to 30 days, and the chain runs on proof of work meanwhile. The node reports the pause. A key that stops signing is reported as absent within two hours, which is how operators see a pause coming. Beneath the latest lock the depth to rely on is the finality depth: a node never switches to a chain forked more than 12 hours of median time back, and a certified checkpoint shortens that to its own age. Kaspa's one-hour merge depth is a limit on which old blocks a new block may merge, not a reorganisation bound. Signing two different checkpoints at the same height is equivocation, provable by anyone, and it strips the key of its vote for 30 days.

What is not here

No coin is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window, and equivocation strips it for 30 days. No coin-holder class votes on anything. No anchoring into Bitcoin or any other chain. Nothing in Igneum's consensus depends on anything outside Igneum.

@@ -528,7 +542,8 @@ body.all .pager{display:none}

Building on Igneum

-

Anything that runs on Ethereum runs on Igneum unchanged. Same Solidity, same bytecode, same wallets, same tools, a different chain id. Builders get Ethereum semantics with one-second inclusion, finality in about two minutes, and gas priced for a chain that is not congested.

+

A GPU-secured network for Ethereum-compatible applications and verifiable computation.

+

Contracts built for Ethereum deploy with the same Solidity, the same bytecode, the same wallets and tools, and a different chain id. Compatibility is shown, not assumed: representative contracts, wallet fee estimation, indexing, failed transactions and receipts are tested as a product deliverable, and the differences are documented (block context, randomness, two-dimensional fees). Builders get Ethereum semantics with one-second inclusion, finality in about two minutes, and gas priced for a chain that is not congested.

Three things Igneum offers at the base layer that we know no other EVM chain offers.

  1. Proving as a native primitive. A contract can request a proof of any computation and pay for it in gas, and the miners produce it. A game proves a fair shuffle. A lending market proves its solvency. A rollup elsewhere posts a job and gets its proof back. We know of no other EVM chain with a prover network in its base layer.
  2. @@ -539,7 +554,7 @@ body.all .pager{display:none}

    Why build here

    Not for speed. Fast EVM chains filled with copied Ethereum contracts and emptied when incentives stopped. Three things no L2 can offer. Keep your Ethereum deployment.

      -
    1. Proofs priced by the subsidy forgone. A contract requests a proof of any computation and the miners produce it. Their cards already run and are paid by emission, so a job has to beat the lottery income the card forgoes while it proves. That is the price a prover must charge, as a formula with network hash as the input: per shard, (card hash ÷ network hash) × 0.8 × 31.688 IGN × shard seconds, plus electricity, which is under a cent per billion cycles on every card. It falls as one over network hash: at the devnet's 1.16 GH/s a quote is 100 to 300x the published market rate; a card proving beside its miner is competitive near 100 GH/s (the Horizon economy lane, 6 October 2026, sections 3.1 and 4.1, approximate beyond the one card measured; ledger E20). Verification is folded into the chain's own proof; you ship no verifier. The job's base fee rises with the backlog, published at the phase 4 job market.
    2. +
    3. Proofs priced by the subsidy forgone. A contract requests a proof of any computation and the miners produce it. Their cards already run and are paid by emission, so a job has to beat the lottery income the card forgoes while it proves. That is the price a prover must charge, as a formula with network hash as the input: per shard, (card hash ÷ network hash) × 0.8 × 31.688 IGN × shard seconds, plus electricity, which is under a cent per billion cycles on every card. It falls as one over network hash: at the devnet's 1.16 GH/s a quote is 100 to 300x the published market rate; a card proving beside its miner is competitive near 100 GH/s (the economy analysis of 6 October 2026, sections 3.1 and 4.1, approximate beyond the one card measured; ledger E20). Verification is folded into the chain's own proof; you ship no verifier. The job's base fee rises with the backlog, published at the phase 4 job market.
    4. Users who were not paid to arrive. Every miner is a funded wallet. Pools, payout contracts, hardware finance and hashrate forwards have customers before any consumer app does. Block rewards can pay straight to a contract.
    5. A share of fees, with the number stated. 20% of every priority fee goes to the contracts whose code ran, per call frame, to the payee registered at deployment. Libraries are paid at their code address. Factories pass their registration to what they deploy. At launch fee levels this is a property, not an income: a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year, with 1 gwei taken as a billionth of an IGN (the base unit is Open). It grows with traffic and nothing else.
    @@ -582,7 +597,7 @@ body.all .pager{display:none} ShareGoes toWhy 80%The miner who wins the blockPays the hashrate that secures the chain - 20%The proving pool: shard provers and aggregatorsFor a standing prover population that does not have to hash. On the devnet today the coinbase's 20% output goes to an unspendable script tagged igneum-proving-pool-v0 and is burned there. Provers are paid from a separate escrow in the execution state, credited by rule with the same 20% of each blue block's subsidy and released per shard against valid proof records (Implemented, proving v0, since 5 October 2026). Caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a block producer could claim shard pay with a false proof (ledger P21; the in-consensus verifier is built and switches on when the proven share of blocks reads one). Note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven segment's pool (0.3.16). Open: the single coinbase payout that replaces the burn, and whether it reclaims the share burned so far + 20%The proving pool: shard provers and aggregatorsFor a standing prover population that does not have to hash. On the devnet today the coinbase's 20% output goes to an unspendable script tagged igneum-proving-pool-v0 and is burned there. Provers are paid from a separate escrow in the execution state, credited by rule with the same 20% of each blue block's subsidy and released per shard against valid proof records (Implemented, proving v0, since 5 October 2026). Caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a block producer could claim shard pay with a false proof (ledger P21; the in-consensus verifier is built; its enforcement, verifier_in_consensus and proof_rule_active_from, is Open and is the prerequisite of the no-rescue network exercise, Deliverable 5). Note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven segment's pool (designed). Open: the single coinbase payout that replaces the burn, and whether it reclaims the share burned so far 0%Treasury, foundation, team or stakeThere is no coin-holder class in consensus and no tax on emission @@ -603,7 +618,7 @@ body.all .pager{display:none}

    Sources: specification sections 2.5 and 5.1 to 5.4; the engineering log for the devnet receipts and the dev-fee count.

    Security after the subsidy

    -

    The cap stays at 4 billion. There is no tail emission. The schedule is a bet, not a measurement: a halving halves emission income overnight if price and fees do nothing. Kaspa's steeper monthly reduction kept its hashrate while its price rose (approximate). Long term, security is paid for by the proving market and by fees. Outside customers buy proofs as dollars-priced work settled in IGN, and 90% of every job goes to the provers who delivered it, so a prover's income does not depend on emission. The table shows the first year in which the block subsidy on its own pays miners less than the power of about 3,000 consumer cards, at three flat prices. The prices are inputs chosen to span two orders of magnitude. The model runs a 300 W card at 124 MH/s on electricity at USD 0.12 per kWh. One rule sits beside the cap. If external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the question of a tail reward goes to the miners' signalling vote. The protocol never changes emission by itself.

    +

    The cap stays at 4 billion. There is no tail emission. The schedule is a bet, not a measurement: a halving halves emission income overnight if price and fees do nothing. Kaspa's steeper monthly reduction kept its hashrate while its price rose (approximate). Long term, security has to be paid by fees and, if it is built and bought, the proving market. The external market is Designed, not built, and is out of the numbers below. As designed, outside customers buy proofs as dollars-priced work settled in IGN, and 90% of every job goes to the provers who delivered it. The table shows the first year in which the block subsidy on its own pays miners less than the power of about 3,000 consumer cards, at three flat prices. The prices are inputs chosen to span two orders of magnitude. The model (modelled, 3 October 2026) runs a 300 W card at 124 MH/s on electricity at USD 0.12 per kWh. One rule sits beside the cap. If external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the question of a tail reward goes to the miners' signalling vote. The protocol never changes emission by itself.

    @@ -637,26 +652,26 @@ body.all .pager{display:none} - +
    Price per IGNFirst year the subsidy alone pays under the power of 3,000 cardsSubsidy to miners that year
    Block rewardEmission, 80% to the winnerYes
    In-chain provingThe 20% proving pool plus the proving share of every block's gas (on the devnet, paid from the execution-state escrow; see Economics)Yes, mostly
    External proving jobsRollups and apps on other chains, priced in their moneyNo, but the market is small today and is upside, not a promise
    External proving jobsRollups and apps on other chains, priced in their money (Designed, not built)No, but the market is not built and is upside, not a promise

    A block pays its miner whether or not anyone buys a proof that day. The lottery pays 80 percent of every block from emission; proving is the second income, never the only one. Every useful-work chain on record dropped its miners the day the work stopped paying; Igneum’s miners are paid for the block first.

    -

    The size of that third stream today, in numbers: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block, 7,200 blocks a day; the tracker figure is a secondary source), against about USD 13,700 a day of Igneum's year-1 emission at USD 0.005 per IGN (31.688 IGN a block, 86,400 blocks a day; the price is an input, not a forecast). So external proving is a small second income at launch and the lottery pays the bills; for proving to become the main income the paid demand would have to grow about 1,000x in dollars (the Horizon lane analysis, 6 October 2026, section 3.11; ledger E19).

    -

    The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' electricity cost in the proving market is close to power. The price they must charge is another matter: the price a prover must charge is the subsidy it forgoes while it proves, which falls as one over network hash, so the edge over data-centre provers appears only once the network's hash is large (near 100 GH/s for a card proving beside its miner) and is nothing more. Which of the two in-chain streams pays more per GPU-second depends on the size of the fleet: on the devnet of 4 October 2026, three machines at 275 million hashes a second, a second of hashing paid about 4.9x a second of proving the pool share; at 10,000 cards the same arithmetic favours proving by about 930x. That is arithmetic on measured devnet rates, approximate, not a market measurement.

    +

    The size of that third stream today, in numbers: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block, 7,200 blocks a day; the tracker figure is a secondary source), against about USD 13,700 a day of Igneum's year-1 emission at USD 0.005 per IGN (31.688 IGN a block, 86,400 blocks a day; the price is an input, not a forecast). So external proving is a small second income at launch and the lottery pays the bills; for proving to become the main income the paid demand would have to grow about 1,000x in dollars (the chip and economy analysis of 6 October 2026, section 3.11; ledger E19).

    +

    The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' electricity cost in the proving market is close to power. The price they must charge is another matter: the price a prover must charge is the subsidy it forgoes while it proves, which falls as one over network hash, so the edge over data-centre provers appears only once the network's hash is large (near 100 GH/s for a card proving beside its miner) and is nothing more. Which of the two in-chain streams pays more per GPU-second depends on the size of the fleet: measured on 4 October 2026, three machines at 275 million hashes a second, a second of hashing paid about 4.9x a second of proving the pool share; at 10,000 cards the same arithmetic favours proving by about 930x. That is arithmetic on measured devnet rates, approximate, not a market measurement.

    Hardware

    -

    The dataset starts at 2 GB and grows (the proposed schedule, fixed at the testnet genesis: 2 GB, doubling at years 4, 12 and 28, the average of half a gigabyte a year), so a 4 GB card mines for about four years and an 8 GB card for about twelve, approximate. Every NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server (eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026). NVIDIA and AMD both work, because the mining program is generated for the architecture both share and the proof system is hash-based. Apple's chips are GPUs with unified memory, so Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second, an Apple M5 Max beside an RTX 5090 on the live devnet, 4 October 2026. A Mac is a poor miner per dollar. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.

    +

    The dataset starts at 2 GB and grows (the proposed schedule, fixed at genesis: 2 GB, doubling at years 4, 12 and 28, the average of half a gigabyte a year), so a 4 GB card mines for about four years and an 8 GB card for about twelve, approximate. NVIDIA cards prove: from 8 GB on the patched server, 12 GB and up beside the miner, 24 GB on the stock server (measured on eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026). NVIDIA and AMD cards both mine, because the mining program is generated for the architecture both share; only NVIDIA cards prove today. Apple's chips are GPUs with unified memory, so Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second, an Apple M5 Max beside an RTX 5090, mining side by side, 4 October 2026. A Mac is a poor miner per dollar. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.

    What a miner's hour looks like

    -

    The card hashes the lottery continuously. When the client sees a shard or an external job it can win, it switches the card to proving for a few seconds, posts the proof, and goes back to hashing. The client does the switching and the miner sees one balance.

    +

    The card hashes the lottery continuously. On an NVIDIA card, when the client sees a shard it can win (or, once the job market is built, an external job), it switches the card to proving for a few seconds, posts the proof, and goes back to hashing. The client does the switching and the miner sees one balance.

    The protocol carries no fee: no dev fund, no cut to any team. Ember, the miner software, takes an optional 1% dev fee, the way other GPU miners do. One block template in 100 is requested with the dev address instead of yours, by a counter, not a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. One flag turns it off (--dev-fee 0, a switch in the app, a line in the HiveOS config). The miner prints the fee and the address when it starts. Any other client is welcome.

    One click, for everyone else

    -

    Farm operators get a HiveOS package. Everyone else gets Igneum Ember: install it on Windows, macOS or Linux, press Start, and the card is mining to a key the app made for you. It is the same client with a face on it. Implemented, Ember 0.3.22 (7 October 2026): the app shows the key once and has you save it before mining starts, or takes an address you already have; the dashboard shows each card's hash rate, blocks found and accepted by the node, the node's height and peers, the next hourly program, the finality votes sent, and a proving tile with shards assigned, submitted and paid and the verifier state; the chain label reads Devnet 3 and the welcome screen says nothing is bought or sold; NVIDIA cards are capped at 80% of their default power limit for stability, with a sweep that looks for the best hash per watt, not yet measured on a card; proving the shards the chain assigns is a switch in Settings (proving v0), beside the 1% dev fee switch, finality voting, and signed updates that install themselves at a quiet moment with a switch to turn that off. It shows no earnings in IGN or in any currency, and it has no hardware-wallet path. Roadmap, Designed and not in the app: earnings per block in IGN with the network named, a figure in your currency, mining paused while you game, and a hardware wallet for your key. Ember is downloaded only from this domain, with the version and size on the button and the hash in the signed manifest the app checks. The next section says what is shipped and what is still a design. Nobody from Igneum will ever ask for your seed. Mining never runs in a browser, because browser compute is slow and browser mining has meant malware since Coinhive. The browser is for the dashboard, and for verifying the chain.

    -

    Testnet terms

    -

    No value. Testnet IGN cannot be sold, bought or redeemed, now or at mainnet. There is no airdrop, no points scheme and no promise tied to testnet balances. Mainnet starts from an empty genesis.

    -

    Resets. The chain restarts from a fresh genesis when a consensus rule changes. Every reset is announced at least seven days ahead on the site and in the app. Balances, contracts and history do not carry over. The devnet that runs today resets without notice.

    +

    Farm operators get a HiveOS package. Everyone else gets Igneum Ember: install it on Windows, macOS or Linux, press Start, and the card is mining to a key the app made for you. It is the same client with a face on it. Implemented in Ember (7 October 2026): the app shows the key once and has you save it before mining starts, or takes an address you already have; the dashboard shows each card's hash rate, blocks found and accepted by the node, the node's height and peers, the next hourly program, the finality votes sent, and a proving tile with shards assigned, submitted and paid and the verifier state; the chain label names the devnet and the welcome screen says nothing is bought or sold; NVIDIA cards are capped at 80% of their default power limit for stability, with a sweep that looks for the best hash per watt, not yet measured on a card; proving the shards the chain assigns is a switch in Settings (proving v0), beside the 1% dev fee switch, finality voting, and signed updates that install themselves at a quiet moment with a switch to turn that off. It shows no earnings in IGN or in any currency, and it has no hardware-wallet path. Roadmap, Designed and not in the app: earnings per block in IGN with the network named, a figure in your currency, mining paused while you game, and a hardware wallet for your key. Ember is downloaded only from this domain, with the version and size on the button and the hash in the signed manifest the app checks. The next section says what is shipped and what is still a design. Nobody from Igneum will ever ask for your seed. Mining never runs in a browser, because browser compute is slow and browser mining has meant malware since Coinhive. The browser is for the dashboard, and for verifying the chain.

    +

    Devnet terms

    +

    No value. Devnet IGN cannot be sold, bought or redeemed, now or at mainnet. There is no airdrop, no points scheme and no promise tied to devnet balances. Mainnet starts from an empty genesis.

    +

    Resets. Devnet 3 may restart from a fresh genesis, without notice. Balances, contracts and history do not carry over.

    What the app sends home. The app version, a random machine id made at install, your operating system, the node version, the hash rate, and the app, node and miner logs (which name the address the card mines to). They go to the project's log intake, a service Igneum runs on its host, and are read by the maintainers to find faults. Never your seed phrase, never a key, never a file you did not make with the app. Nothing is sold or shared.

    Wallet set-up for MetaMask: chain id, RPC and the one-click button. The miner software takes an optional 1% fee, off with one flag; the protocol carries no fee to anyone.

    Fair launch, announced

    -

    Launch date and miner software published a month ahead. Pools live on testnet. HiveOS support on day one. The founders mine from genesis like everyone else, with disclosed addresses and the same software. Nobody has coins before block one. The first 30 days of mainnet run on proof of work alone, with no locked checkpoint, while vote weights build; anyone crediting deposits in that month should treat Igneum as plain proof of work with a 12-hour depth.

    +

    Launch date and miner software published a month ahead. Pools live before launch. HiveOS support on day one. The founders mine from genesis like everyone else, with disclosed addresses and the same software. Nobody has coins before block one. The first 30 days of mainnet run on proof of work alone, with no locked checkpoint, while vote weights build; anyone crediting deposits in that month should treat Igneum as plain proof of work with a 12-hour depth.

@@ -686,12 +701,12 @@ body.all .pager{display:none} 1. Compiler race every hourAt every hourly program the worker compiles up to 17 variants of the kernel (unroll, load path, register budget, threads per block), checks each bit for bit against the base kernel, times each for 2 s with mining paused, and keeps the fastest for the hour. The hash output is bit for bit the sameShipped in the Metal and CUDA workers+17.3% on the genesis seed and +21.2% on the hourly seed, Apple M5 Max, Metal, 14 variants, under load, ratios only. The RTX 5090 race is built and not yet run 2. Per-card auto-tune from the fleetEvery race writes a record to the fleet log. The best variant per card model is aggregated and sent back to every machine inside the signed update manifest, so a new card starts from the fleet's best and keeps racingShipped. The fleet is small, so no table yetNo fleet table yet 3. Hash per wattSteps an NVIDIA card's power cap from 100% to 50% of its default in 10% steps, holds each for 60 s, and keeps the best MH per watt. The tile shows live MH per watt. The sweep never restarts the worker, so the hour's program is never lostIn the app for NVIDIA cards. AMD and Apple: not supportedThe first sweep on a card is pending. The RTX 5090 drew 290 W at p95 under a 460 W cap, so the cap did not bind - 4. Template latencyThe miner subscribes to new templates instead of polling, the node builds the next template ahead, and the workers switch without draining the batch. Target under 50 ms from a new block to the card working on it, solo against the local nodeIn 0.3.6Switched p50 46 to 52 ms, p90 118 to 130 ms, 3-node fast-time network, CPU miners, 0 rejected - 5. Never lose a secondThe next hour's program is compiled ahead and swapped in place. The watchdog, the restarts, the CPU re-check of every found hash and per-worker health on every tile keep the card hashingShippedSwap 0.01 ms on the Mac and 0.00 ms on the RTX 5090, 0 rejected, live devnet. Fake-worker guards: trip 0.0 s, worker back in 2.0 s; a silent worker restarted at 60 s + 4. Template latencyThe miner subscribes to new templates instead of polling, the node builds the next template ahead, and the workers switch without draining the batch. Target under 50 ms from a new block to the card working on it, solo against the local nodeShippedSwitched p50 46 to 52 ms, p90 118 to 130 ms, 3-node fast-time network, CPU miners, 0 rejected + 5. Never lose a secondThe next hour's program is compiled ahead and swapped in place. The watchdog, the restarts, the CPU re-check of every found hash and per-worker health on every tile keep the card hashingShippedSwap 0.01 ms on the Mac and 0.00 ms on the RTX 5090, 0 rejected, mining live. Fake-worker guards: trip 0.0 s, worker back in 2.0 s; a silent worker restarted at 60 s 6. Prove it in publicEvery measured rate, with the card, the miner version, the date and the log entry it came from, on one pageLiveThe bench table -

Measured: engineering log, "miner performance: variant racing" (lever 1), "first hourly program swap on the live devnet" and "miner fault guards and the app watchdog" (lever 5), 4 October 2026; the 0.3.6 release plan, the miner-latency gate (lever 4), 5 October 2026; the efficiency-sweep plan, the RTX 5090 log of 4 October 2026 (lever 3). Levers 2 and 3 are shipped code with no fleet measurement yet.

+

Measured: engineering log, "miner performance: variant racing" (lever 1), "first hourly program swap" and "miner fault guards and the app watchdog" (lever 5), 4 October 2026; the miner-latency gate (lever 4), 5 October 2026; the efficiency-sweep plan, the RTX 5090 log of 4 October 2026 (lever 3). Levers 2 and 3 are shipped code with no fleet measurement yet.

The software's fee, not the protocol's

The protocol is fee-free: no dev fund, no fee to any team, foundation or fund. Ember takes a 1% software dev fee, the norm for GPU miners: default-on, switchable, 1 percent of the producer share (the 80% of emission that pays the block's miner; the proving pool is paid per record and carries none of it). One block template in 100 is requested with the dev address instead of yours, by a counter, never a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. A fee block still carries your vote key, so it still adds to your finality weight. Ember prints the fee and the address when it starts, shows it in Settings next to a switch, and --dev-fee 0 turns it off, as does DEV_FEE=0 in a HiveOS flight sheet. Any other client is welcome.

Measured: engineering log, "the software dev fee measured on a test network", 4 October 2026: 9 fee blocks in 785 from two fee-paying miners, 0 from the control at --dev-fee 0, the chain and the miners' counters equal.

@@ -722,17 +737,17 @@ body.all .pager{display:none} NextTouch ID and Windows Hello to unlock. In progress, not live. Windows build: next -

Source: Igneum Wallet 0.1.1, 5 October 2026, now 0.1.5 on the downloads host (the wallet source: the vault, HD key, finality, QR and updater modules and the README). Verified: the over-the-air path end to end on one Mac against a test manifest. Not yet run: the Windows path, the rollback paths, a Developer ID signature.

+

Source: Igneum Wallet, first shipped 5 October 2026, on the downloads host (the wallet source: the vault, HD key, finality, QR and updater modules and the README). Verified: the over-the-air path end to end on one Mac against a test manifest. Not yet run: the Windows path, the rollback paths, a Developer ID signature.

Governance

-

Igneum is governed by the hashrate that powers it. Pools carry their hashers' votes, so pool concentration is the governance risk, and it is public: on the devnet the top three vote keys held 34.5% of 8,090 blocks on 4 October 2026, measured.

+

Igneum is governed by the hashrate that powers it. Today, as built, pools carry their hashers' votes, so pool concentration is the governance risk, and it is public: on the devnet the top three vote keys held 34.5% of 8,090 blocks on 4 October 2026, measured.

  • Nothing needs a scheduled upgrade. The mining program, the dataset and the finality rules run themselves for ever. If the community ever ships an improvement, a better proof system or a block-rate step, it is published with test vectors at least three months ahead and activates only when 90% of blocks signal readiness. Developers can write code. Only miners can turn it on.
  • Miners set what genesis leaves open. Miners signal three things at three thresholds: 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. There is no fund to vote on and no fee to any team, foundation or fund.
  • -
  • Pools can be bypassed on transaction choice. Igneum ships Stratum v2 job declaration from day one, so a miner chooses its own transactions when its pool supports it. Pools can decline, and vote keys stay with the pool. Designed: the pool protocol is specification section 9, not yet run by any pool.
  • -
  • There are no admin keys in consensus. Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy. The genesis apps are contracts, and each publishes its own upgrade and key policy before launch; the bridge's is the one to read. Designed, open item O-5.4. On the devnet the activation heights and one execution-state restart (6 October 2026) reach every node through the signed update manifest, so on the devnet the release key acts as the operator; the sentence above holds for mainnet consensus only once that path is closed, and the public testnet terms will say which parameters still travel that way.
  • +
  • Pools can be bypassed on transaction choice. Igneum ships Stratum v2 job declaration from day one, so a miner chooses its own transactions when its pool supports it. Pools can decline. Designed: the pool protocol is specification section 9, not yet run by any pool. Vote keys stay with the miner at protocol level: the member's retained voting key is committed into its work, payment aggregation is separate and verifiable, and pool identity substitution is resisted (a pin of Igneum 2.0, pools and participation; not yet shipped).
  • +
  • There are no admin keys in consensus. Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy. The genesis apps are contracts, and each publishes its own upgrade and key policy before launch; the bridge's is the one to read. Designed, open item O-5.4. On the devnet the activation heights and one execution-state restart (6 October 2026) reach every node through the signed update manifest, so on the devnet the release key acts as the operator; the sentence above holds for mainnet consensus only once that path is closed, and the network's terms will say which parameters still travel that way.
  • The chain runs without its founders. Blocks, proofs and finality need no one. A second independent node client is the first priority after launch, and anyone can build it.
@@ -745,35 +760,21 @@ body.all .pager{display:none} 1. SpecificationUnder way; closes when the specification is out for external reviewMining generator, shard proving, finality rules, written for external review 2. Prove the provingUnder way; closes at its gateMining program prototype on GPU and CPU, shard proving benchmark on consumer cards. So far: an RTX 5090 proves a shard in 10.9 s compressed; a CPU verifies a warp in 0.61 ms (class v2) to 2.1 ms (class v3). A mid-range card has not been measuredA mid-range GPU proves a shard in under 20 s and a CPU verifies a hash in 10 ms - 3. DevnetDevnet 3 live since 7 October 2026; closes at its gateBlockDAG node with the new mining program and EVM execution. Live now on Devnet 3, every upgrade on from block zero: class v4, the era VDF, difficulty v2, finality v3 (first lock 20:02 UK, 7 October 2026), proving v0 and v1, the ladder at rung 0, calibrated fees, Ember 0.3.22 on every machine. Measured on the first devnet on 6 October 2026: proofs landed a median of about 380 s behind the tip (the observer, /live), against the 60 s gate; Devnet 3's proof lag and proven share are read from the observer as the fleet publishes them1 block a second held with proofs under 60 s behind the tip - 4. Finality and job marketCloses when the finality design passes external review and one rollup signs for the testnetSustained-mining finality, external proving jobs, miner client with auto-switchingFinality design passes external review and one rollup signs for testnet - 5. Public testnetArmed: opens on the go wordOne-click miner app on Windows, macOS and Linux, HiveOS, pools, the first rollup as a proving customer, no coin yet1,000 independent miners run 30 days and rollup proofs are delivered on time - 6. Mainnet fair launchAfter the testnet has passed its gate: 1,000 independent miners for 30 days and rollup proofs on timeGenesis with no premine, 30-day ramp. No listing is arranged, promised or sought by the project + 3. DevnetUnder way; closes at its gateBlockDAG node with the new mining program and EVM execution, every upgrade on from block zero: class v4, the era VDF, difficulty v2, finality v3, proving v0 and v1, the ladder at rung 0, calibrated fees, Ember on every machine. The devnet's proof lag and proven share are read from the observer as the fleet publishes them1 block a second held with proofs under 60 s behind the tip + 4. Finality and job marketCloses when the finality design passes external review and one external customer pays for repeat proving jobsSustained-mining finality, external proving jobs, miner client with auto-switchingFinality design passes external review and one external customer pays for repeat jobs of its exact workload + 5. No-rescue network exerciseOpen; starts once proof verification is enforced in consensusNo founder-operated mining, proving, aggregation or distribution. Epoch boundaries crossed, signing interrupted, the network partitioned, major operators removed, hostile proof submissions, independently written clients, a withholding prover replaced. One-click miner, HiveOS, pools, no coin yetSpecified behaviour with no emergency algorithm change and no privileged intervention; 1,000 independent miners run 30 days + 6. Mainnet fair launchAfter phase 5 has passed its gateGenesis with no premine, 30-day ramp. No listing is arranged, promised or sought by the project

Dates slip. Gates do not. Phase two decides everything. If consumer GPUs cannot prove shards fast enough, Igneum says so and does not launch on promises.

-

The 0.3.6 release plan, 5 October 2026

-

The proving activation of 5 October 2026 set the next release. The table is the plan as written; Ember has since reached 0.3.22 (7 October 2026), and each item's state is in the engineering log.

-
- - - - - - - - - -
ItemWhy
Ember's node runs the proof verifierOn 5 October no node on the network ran one, so a producer stored proofs and never paid them. The app now points its node at the shipped prover host
The Windows package ships the prover hostA PC needed a 20-minute setup by hand before it could prove
The proving tile shows the verifier stateA node that relays proofs but never pays them says so, on the tile and on the live page
Template latencyLever 4 above: subscribe, pre-warm, switch without draining. Switched p50 46 to 52 ms on the gate run
Instant jobsA job published to the fleet reached a machine up to 10 minutes later. The app now holds an outbound connection and fetches the moment a job is published, 3 to 6 s expected, not yet measured
Testnet parameters behind a height switchThe testnet identity and the fee floors adopted on 5 October 2026, so the devnet is never forked by a node update
-

Source: the 0.3.6 release plan, 5 October 2026. The latency number is the plan's gate run on a 3-node fast-time network with CPU miners; the instant-jobs latency is an estimate until the first measured row.

Questions miners ask

Kaspa was GPU-mined too, and IceRiver shipped a chip within two years.

-

Kaspa never promised chip resistance, and its hash was one fixed function, simple enough to put on silicon. Igneum's program is different every hour, its dataset grows past any fixed memory, and its program space widens every era, with no human involved. The public benchmark with a leaderboard ships with the public testnet, and its source is public with the repository then, so you run it on your own card and post the number. The in-house adversarial pass and the public benchmark are where a chip design that beats a GPU by more than 2x would show. And if a chip ever appears, miners are the ones who signal the response.

+

Kaspa never promised chip resistance, and its hash was one fixed function, simple enough to put on silicon. Igneum does not claim a chip cannot be built. It assumes one exists and scores it: the chip model states the energy advantage, the economic advantage and the response capability separately. The public benchmark with a leaderboard is owed work, and so is the comparison against operating GPU networks: Ravencoin's KAWPOW, Ergo and Firo's reference miner. No result exists yet. The in-house adversarial pass and the public benchmark are where a stronger chip design would show. And if a chip ever appears, miners are the ones who signal the response.

Don't ASICs make a chain safer?

-

Three parts. First, what the chain asks hash to do. Hash picks who makes the next block. It does not protect history. A checkpoint locks when signatures reach two thirds of the weight of the last 30 days of blocks (specification section 3). A locked checkpoint is never reorganised by any amount of hash: fork choice runs among the tips that pass through every certified checkpoint. Rented hash has no weight today. It can mine blocks. It cannot rewrite anything older than a lock. A renter with 60% of the network holds 0.0% of the vote on day one (the finality simulator, table B); one matching the whole honest network reaches a third of the weight on day 20 and never two thirds. The lock is fast: median 1,018 ms behind the checkpoint on the three-node test network (engineering log, the finality harness), and on the live devnet the first lock came two hours after genesis, once the window was full. Reorganisations under the lock are shallow: at 1, 2 and 5 blocks a second the deepest honest reorganisation measured was 2, 3 and 7 blocks against a determination depth of 20 (ledger F7, round 2, the fast-time network with 100-ms links); across five continents blocks reached every node at p50 343 ms and p99 666 ms (the 12-node cloud network, 4 October 2026).

+

Three parts. First, what the chain asks hash to do. Hash picks who makes the next block. It does not protect history. A checkpoint locks when signatures reach two thirds of the weight of the last 30 days of blocks (specification section 3). A locked checkpoint is never reorganised by any amount of hash: fork choice runs among the tips that pass through every certified checkpoint. Rented hash has no weight today. It can mine blocks. It cannot rewrite anything older than a lock. A renter with 60% of the network holds 0.0% of the vote on day one (the finality simulator, table B); one matching the whole honest network reaches a third of the weight on day 20 and never two thirds. The lock is fast: median 1,018 ms behind the checkpoint on the three-node test network (engineering log, the finality harness), and with a two-hour window the first lock came two hours after genesis, once the window was full. Reorganisations under the lock are shallow: at 1, 2 and 5 blocks a second the deepest honest reorganisation measured was 2, 3 and 7 blocks against a determination depth of 20 (ledger F7, round 2, the fast-time network with 100-ms links); across five continents blocks reached every node at p50 343 ms and p99 666 ms (the 12-node cloud network, 4 October 2026).

Second, the cost the ASIC argument skips. Kaspa's hash went to a handful of chip owners within months: the IceRiver KS0 shipped in July 2023, 17 to 20 months after launch; hashrate went from under 100 PH/s to over 700 PH/s in months and the GPU share was negligible by late 2023 (the ASIC history, row 23, approximate for the share). Bitcoin's hash comes from two manufacturers and a few pools (approximate, from memory). The first chip's owner mines in secret with an edge for months: on Monero, 85% of the hashrate vanished at the April 2018 fork, and chips were found at over 85% again four months after the next fork (row 16). A chip does not add security to a chain; it moves the chain's security to whoever owns the chip first.

Third, the honest part. A young GPU chain's hash is cheap to rent, and we publish the number beside the chain's own. The locks are what make that rental unable to buy a double-spend: a deposit under a lock stays, whatever the renter mines on top. Ethereum Classic (January 2019 and August 2020), Bitcoin Gold (May 2018 and January 2020) and Vertcoin (October to December 2018, December 2019) were reorganised with rented hash (the ASIC history rows 6 and 7 for Bitcoin Gold and Vertcoin; the Ethereum Classic dates approximate, from memory); Verge's 2018 reorganisations used a timestamp flaw in its multi-algorithm rule as well as hash (approximate). On those chains the rented hash rewrote history because nothing but hash held it. Here the same rental mines blocks for its hour and leaves the locks where they were. The exception is stated above: in the first 30 days of mainnet no checkpoint locks, the chain is plain proof of work with a 12-hour depth, and a rental can reorganise inside that depth; anyone crediting deposits in that month treats it so.

@@ -790,9 +791,9 @@ body.all .pager{display:none}

Correct, and it is the first thing the external review will be paid to break. The specification is public; reviewers will be named and paid before gate 3, and the public benchmark carries the metrics they test against. Until then every finality claim here is a design claim backed by simulations and by the devnet, and the chain runs on plain GHOSTDAG without the rule, so it can be fixed without stopping the chain.

Who are you?

One founder, pseudonymous, working with AI systems. The design, the hostile reviews, the code, the simulators and this document were produced that way, and the commit history says so. The software is shipped by Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre. The design remains the work of one founder working with AI systems, reviewed in public through the ledger. What that does and does not mean: the measurements are measurements, reproducible from the commands in the engineering log; the simulators are code anyone can run; the design claims stay design claims until people with names have tried to break them. Every criticism the project expects is kept in a ledger with its honest answer, and the entries that were right are marked conceded; the ledger is public at /ledger. No cryptographer is hired yet; the plan budgets one for phases 1 and 2, and external reviewers are named and paid before gate 3.

-

The founders mine from genesis with disclosed addresses and the same software as everyone else, and hold no coins before block one. The team is pseudonymous and there is no team page. The mining addresses are published at the public testnet; the code history is published with the repository.

+

The founders mine from genesis with disclosed addresses and the same software as everyone else, and hold no coins before block one. The team is pseudonymous and there is no team page. The mining addresses are published before launch; the code history is published with the repository.

Where is the miner?

-

On the devnet now. Igneum Ember runs on Windows, macOS and Linux, a HiveOS package exists, and the devnet's coins have no value. The public benchmark with a leaderboard ships with the public testnet. Pools come with it. The public testnet is armed: three seed nodes and the public RPC are up, and it opens on the go word. All of it before any coin exists. Nothing is asked of a miner before they can run something. The Ember section says what is shipped and what is still owed.

+

On the devnet now. Igneum Ember runs on Windows, macOS and Linux, a HiveOS package exists, and the devnet's coins have no value. The public benchmark with a leaderboard and the pools are owed before launch. All of it before any coin exists. Nothing is asked of a miner before they can run something. The Ember section says what is shipped and what is still owed.

Will my card still pay in a bear market?

Block reward and in-chain proving move with the price. Proving for other chains is priced in the customer's money, and it is a small market today. What Igneum can promise is that its miners' electricity cost in that market is close to power, because the card is already running on domestic power; the price they must charge is the subsidy they forgo, which falls as one over network hash. That is an edge over data-centre provers at scale and nothing more.

@@ -804,7 +805,7 @@ body.all .pager{display:none}

What does a one-minute proof mean for my app?

Nothing you wait for. Your transaction executes in about a second. A miner lock arrives in about two minutes and that is the finality your contract sees. The proof follows and makes the state unforgeable. Liquidations and trades act on executed state at once, as on any chain. A bridge built on Igneum waits for the lock, about two minutes.

Which stablecoin, and is there liquidity?

-

None is bridged at genesis, and no bridge is official. The project will ask Circle for native USDC during the public testnet; whether it is issued is Circle's decision. Anyone may run a bridge at their own risk until the proof bridge arrives with the consensus proof in phase two. The DEX is seeded at launch by the founders' own mined coins and by miners, and every miner is a funded wallet.

+

None is bridged at genesis, and no bridge is official. The project will ask Circle for native USDC before launch; whether it is issued is Circle's decision. Anyone may run a bridge at their own risk until the proof bridge arrives with the consensus proof in phase two. The DEX is seeded at launch by the founders' own mined coins and by miners, and every miner is a funded wallet.

What do I get for being early?

20% of the priority fee on every transaction that runs your code, paid to you every block, which at launch fee levels is small and stated as such above. A place in the wallet's Apps tab and the explorer from day one. First access to the proving precompile and the job market. And a user base that was not paid to arrive: the miners.

How do I deploy?

@@ -834,7 +835,7 @@ body.all .pager{display:none}

Here are the limits, stated before anyone else states them.

  • A proof in seconds. Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.
  • -
  • A chip is impossible. No. A chip wired for one program is a bad bet, because the program moves before it ships. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the Horizon lane analysis, 6 October 2026, section 5.4; ledger M32). Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling places the strongest specialised designs assessed against the GPU tier at about 2.3x to 3.3x energy-efficiency advantage a node ahead (2.0x to 2.9x on the GPU's own node), a bracket that is approximate and provisional until the placed gated core rows land. The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment. The labels: the bracket modelled, approximate and provisional (the GPU side measured on the RTX 5080 and RTX 5090 at their core locks under class v4, 8 October 2026; the chip core synthesised on ASAP7 and scaled to N3, claimed, its placed gated row pending; its memory modelled). Class v5 makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the class v6 close, section 10 (8 October 2026); the ASIC history’s Ethash rows; the chip model analysis (6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held its miners on commodity hardware for about seven years: one chip shipped against it, Bitmain’s Antminer X5 (September 2023), an observed comparison, not a ceiling; the one announced beyond it, the Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core never measured; RandomX v2 was released on 25 March 2026 with its activation pending. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.
  • +
  • A chip is impossible. No. Igneum assumes a chip exists. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the chip and economy analysis of 6 October 2026, section 5.4; ledger M32). Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling places the strongest specialised designs assessed against the GPU tier at about 2.3x to 3.3x energy-efficiency advantage a node ahead (2.0x to 2.9x on the GPU's own node), a bracket that is approximate and provisional until the placed gated core rows land. The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment. The labels: the bracket modelled, approximate and provisional (the GPU side measured on the RTX 5080 and RTX 5090 at their core locks under class v4, 8 October 2026; the chip core synthesised on ASAP7 and scaled to N3, claimed, its placed gated row pending; its memory modelled). Class v5 makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026; under evaluation (Deliverable 3), not counted as a defence until justified or dropped). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the class v6 close, section 10 (8 October 2026); the ASIC history’s Ethash rows; the chip model analysis (6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held its miners on commodity hardware for about seven years: one chip shipped against it, Bitmain’s Antminer X5 (September 2023), an observed comparison, not a ceiling; the one announced beyond it, the Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core never measured; RandomX v2 was released on 25 March 2026 with its activation pending. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.
  • A guaranteed income floor. No. External proving is a small market today. Igneum's miners' electricity cost in it is close to power, but the price they must charge is the subsidy they forgo, which falls as one over network hash: an edge at scale and nothing more.
  • A memory-hard prototype on every vendor. Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.
  • Finality in the first month. No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.
  • @@ -842,9 +843,13 @@ body.all .pager{display:none}
  • Finality that no amount of hardware can break. No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded by the 12-hour finality depth. Reaching a third takes at least ten days of producing every block on the chain, in public; an attacker matching the honest network needs twenty days for a third and never reaches two thirds. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose. The floor is also bounded in time: an honest partition that lasts long enough for each side's own new blocks to reach two thirds of its window locks on both sides, about ten days of a 30-day window at an even split, and an operator must then resolve it (measured on a test network, 4 October 2026).
  • Finality that never pauses. No. A lock needs two thirds of all 30-day mining weight. Whenever less than two thirds of that weight is connected and signing, finality pauses until it returns or ages out of the window, up to 30 days. The chain keeps running on proof of work and the node reports the pause.
  • A label that costs nothing. No. Some investors and exchanges read "GPU-mined" as 2021 whatever the proofs do, and nothing here measures that cost. The only evidence will be whether the first miner apps and verifiable-compute apps sign despite the label.
  • -
  • A chain you can debug today. Not yet. The node does not serve debug_traceTransaction, eth_subscribe or eth_getProof, and there is no public RPC, faucet or explorer for the devnet. They come in a fixed order (docs and templates, then the tracing and subscription RPCs, then a public RPC, listing and faucet, then the explorer) and no outside team is invited to build before the second step is done.
  • +
  • A chain you can debug today. Not yet. The node does not serve debug_traceTransaction, eth_subscribe or eth_getProof. The explorer, the faucet and the reference apps run on the devnet; the tracing and subscription RPCs are still owed.
  • A veto on job results. No. A segment proof is checked against every node's own execution; a proving job for another chain is not, because no full node can re-run an arbitrary program, so a soundness bug in the proof system in force reaches the requesting contract. A job output can mint nothing and touch no system contract, and an app that acts irreversibly on a job result keeps its own fallback.
  • A delay function that outlives a quantum computer. No. The class-group delay between a locked checkpoint and the next program seed falls to the same machine that would forge the vote keys; it is flagged in the specification, not yet sized, and the fallback is a hash-chain delay behind the same version byte that moves the signature scheme, so both flip in one class change. A grindable hourly seed is a liveness nuisance against the lottery, not a break of finality.
  • +
  • Proof verification in consensus. Not yet. Today, under proving v0, every producer verifies off the consensus path, and consensus checks the record's statement against native execution. Enforcement in consensus (verifier_in_consensus, proof_rule_active_from) is Open, and it is the prerequisite of the no-rescue network exercise (Deliverable 5) and of the proving economy being a protocol guarantee.
  • +
  • Proving on every card. No. NVIDIA proves; AMD and Apple mine. The proving stack is judged on the full pipeline: inputs, proving, aggregation, verification, payment, memory and the mining income forgone.
  • +
  • What proofs do not give. Proven execution is not finality. EVM compatibility is not Ethereum security. ZK is not privacy.
  • +
  • A ranking. No. Igneum makes no leading or number-one claim. Benchmarks against Ravencoin's KAWPOW, Ergo and Firo's reference miner are owed work; no result exists yet.
  • A finished protocol. The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.

Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything. Found an error, or a criticism this document does not answer? Email hello@igneum.network, or open an issue on the public specification repository: git.igneum.network/igneum-network/spec/issues. Post reaches Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre.

diff --git a/site/metamask.html b/site/metamask.html index 2d788e2b7..1b6213fd0 100644 --- a/site/metamask.html +++ b/site/metamask.html @@ -251,7 +251,7 @@ ol{margin:0 0 14px;padding-left:22px}li{margin-bottom:6px}
Public testnet · coming

Igneum testnet

-

The network the one-click miner app joins at public testnet. Coins on it have no value and the chain resets with notice (testnet terms).

+

The network the one-click miner app joins at public testnet. Coins on it have no value and the chain resets with notice (devnet terms).

Network name
Igneum Testnet
Chain id
4462 (0x116e)
diff --git a/site/randomx.html b/site/randomx.html index 02ee3b306..75d971f1e 100644 --- a/site/randomx.html +++ b/site/randomx.html @@ -254,15 +254,15 @@
- + - +
Hardware it is built forCPUs. GPUs run it badly on purposeGPUs. Any card, any vendor. Bit-exact on Apple, NVIDIA and AMD, measured
Random programPer hash, interpreted in a virtual machinePer hour, compiled to native GPU code. Per hash, the 128 dataset addresses change with the nonce
DatasetAbout 2 GB, the same size since 2019, approximate2 GB, growing (the proposed schedule, fixed at the testnet genesis: 2 GB, doubling at years 4, 12 and 28); a 4 GB card mines about four years, an 8 GB card about twelve, approximate
DatasetAbout 2 GB, the same size since 2019, approximate2 GB, growing (the proposed schedule, fixed at genesis: 2 GB, doubling at years 4, 12 and 28); a 4 GB card mines about four years, an 8 GB card about twelve, approximate
Light verification256 MB cache on a CPU, milliseconds256 MB cache on a CPU (512 MB from year 4), one warp under 10 ms, the gate. Measured 2.1 ms on one Apple M5 Max core for class v3 (3.4x class v2's 0.61 ms); a 2019-class core not yet
Changes over timeNone. A fixed design, unchanged for seven yearsA new program every hour, its memory pattern with it; era draws and reserved families on a schedule fixed at genesis. Nobody touches it
Seed grindingNot applicable, the program comes from the hash inputClosed by a verifiable delay between seed and program
Useful workNone. Hashing onlyEvery NVIDIA card from 8 GB proves; 12 GB and up mine and prove; 24 GB on the stock server (eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026); they sell proofs to other chains. AMD and Apple cards mine, and a prover for them lands when a zkVM ships one
Useful workNone. Hashing onlyNVIDIA cards prove: from 8 GB on the patched server, 12 GB and up beside the miner, 24 GB on the stock server (measured on eleven rented cards, RTX 3060 to RTX 5090, 6 October 2026). Selling proofs to other chains is Designed, not built. AMD and Apple cards mine and do not prove; a prover for them lands when a zkVM ships one
Track recordAbout seven years with one shipped chip, Bitmain’s Antminer X5 (September 2023), at 1.46x per joule over a desktop CPU; the one announced beyond it, Bitmain’s Antminer X9, was withdrawn in May 2026 with zero units; RandomX v2 released 25 March 2026, activation pendingZero years. Every number above is measured and logged with the commands that produced it. The specification, reference hash, test vectors and simulators are public now (git.igneum.network/igneum-network/spec). The node, the miner and the wallet follow to the same host as the repository is published
-

Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Those are prototype figures, not mining rates. The first prototype dataset was a closed-form function, and a miner could compute items instead of loading them: measured 111x faster that way on the Mac. The 256 MB cache construction replaced it on 3 October 2026. With the cache, computing items on the fly runs 4.8x slower than loading them, measured on the Mac, and the honest rate is unchanged on both vendors. Open: the same shortcut ratio on NVIDIA and on a discrete AMD card, and the time-memory trade-off between the two measured points. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. On 4 October 2026 the live devnet crossed an hourly program change on all three vendors with no pause and no rejected block: a Mac at 26.7 million hashes a second, an RTX 5090 at 123 million and an integrated AMD chip at 2.7 million, every hash doing 128 distinct reads of the memory-hard dataset.

+

Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Those are prototype figures, not mining rates. The first prototype dataset was a closed-form function, and a miner could compute items instead of loading them: measured 111x faster that way on the Mac. The 256 MB cache construction replaced it on 3 October 2026. With the cache, computing items on the fly runs 4.8x slower than loading them, measured on the Mac, and the honest rate is unchanged on both vendors. Open: the same shortcut ratio on NVIDIA and on a discrete AMD card, and the time-memory trade-off between the two measured points. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. On 4 October 2026 a live network crossed an hourly program change on all three vendors with no pause and no rejected block: a Mac at 26.7 million hashes a second, an RTX 5090 at 123 million and an integrated AMD chip at 2.7 million, every hash doing 128 distinct reads of the memory-hard dataset.

From dda5dedf44c3c79601d020bb41469a501d53a030 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 15:40:33 +0000 Subject: [PATCH 2/6] Site reset to Igneum 2.0, first pass: /bench and /journey gone, no testnet, no 0.x history, the Igneum 2.0 devnet, the positioning line - build.mjs no longer writes bench.html, journey.html or journey.json; the three files are deleted; /bench -> /evidence and /journey -> /live redirects (permanent: false); nav, footer, sitemap, capture routes and the site-nav-check groups drop them; link-check resolves literal vercel.json redirects and lists every link that leans on one (evidence.html: /bench, another hand) - every testnet card, column, row, notice and link removed from the pages this lane owns; release manifest: the testnet entry gone, network igneum-devnet-4 "Igneum 2.0 devnet", the Devnet 3 genesis, digest, vote domain and floor lines dropped - "Devnet 3" leaves every owned page; the devnet state is one constant in build.mjs (DEVNET_STATE, 'starting' now: the nav pill and the homepage badge read "Igneum 2.0 devnet starting"; 'live' flips both and re-enables the nav's live read) - no 0.x release history: screenshot alt texts say the current build, the miner page's "Current build:" keeps the data-rm spans without the node version; miner-bench.json keeps the current-program rows only, no Counter ASIC names, no versions; /miners drops the earlier-classes table, the history note and the miner-version column - /income keeps the calculator; the testnet-era tier tables (docs/analysis/income-tiers.md) are not served - the positioning line is the first line of the footer partial (every page), the homepage meta description's first sentence and the hero's sub-line; share metas (site/og/pages.mjs) carry no Devnet 3 or zkEVM - ledger-text-check is red on two index.html pins (X2, X31: the testnet sentences), owned by the ledger hand Co-Authored-By: Claude Fable 5.1 --- docs/build/README.md | 8 +- docs/build/build.md | 32 +- docs/build/faucet.md | 9 +- docs/build/first-contract.md | 16 +- docs/build/grants.md | 8 +- docs/build/rpc.md | 10 +- docs/provenance.md | 10 +- site/404.html | 22 +- site/address.html | 39 +- site/app.html | 72 +- site/bench.html | 1092 --------------------------- site/block.html | 33 +- site/build.html | 34 +- site/build.mjs | 160 +--- site/claims.html | 19 +- site/dev-fee.html | 23 +- site/download.html | 20 +- site/economics.html | 56 +- site/evidence.html | 19 +- site/explorer.html | 53 +- site/faucet.html | 46 +- site/grants.html | 29 +- site/income-calc.js | 6 +- site/income.html | 67 +- site/index.html | 31 +- site/journey.html | 376 --------- site/journey.json | 254 ------- site/ledger.html | 19 +- site/light.html | 40 +- site/litepaper.html | 21 +- site/live.html | 19 +- site/metamask.html | 69 +- site/miner-bench.json | 240 ++---- site/miner.html | 51 +- site/miners.html | 52 +- site/og/pages.mjs | 33 +- site/oracle.html | 52 +- site/partials/footer.html | 5 +- site/partials/nav.html | 14 +- site/partials/terms.html | 2 +- site/provenance.html | 23 +- site/proving.html | 39 +- site/randomx.html | 19 +- site/receipt.html | 34 +- site/release-manifest.json | 33 +- site/scenes.html | 19 +- site/site.css | 2 + site/sitemap.xml | 2 - site/swap.html | 71 +- site/tx.html | 39 +- site/vercel.json | 24 +- site/wallet.html | 26 +- tools/ci/link-check.mjs | 13 +- tools/ci/release-manifest-check.mjs | 2 +- tools/ci/site-nav-check.mjs | 2 +- tools/launch/income-page.mjs | 52 +- tools/site/capture.sh | 2 +- 57 files changed, 667 insertions(+), 2896 deletions(-) delete mode 100644 site/bench.html delete mode 100644 site/journey.html delete mode 100644 site/journey.json diff --git a/docs/build/README.md b/docs/build/README.md index 4789d31fa..5133a9999 100644 --- a/docs/build/README.md +++ b/docs/build/README.md @@ -6,11 +6,11 @@ |---|---| | `build.md` | [igneum.network/build](https://igneum.network/build): what is different (built to prove every block, a lock in minutes, nothing to stake, the EVM unchanged), the chain ids and endpoints, the wallet, the explorer, the faucet, the five-minute contract, the browser verifier | | `grants.md` | [igneum.network/grants](https://igneum.network/grants): the tiers, what a grant is, how to apply, the review, the honest lines | -| `first-contract.md`, `first-contract-test.sh` | the walkthrough and the script that runs it end to end on Devnet 3 from a build box; the PASS line is the test record | -| `rpc.md` | the JSON-RPC method list as the node serves it, read from a Devnet 3 node, with the probe | -| `faucet.md` | the Devnet 3 faucet: rules, where it runs, how it is funded | +| `first-contract.md`, `first-contract-test.sh` | the walkthrough and the script that runs it end to end on the devnet from a build box; the PASS line is the test record | +| `rpc.md` | the JSON-RPC method list as the node serves it, read from a devnet node, with the probe | +| `faucet.md` | The devnet faucet: rules, where it runs, how it is funded | | `verify-a-block.md` | the in-browser checkpoint verifier, twelve lines | The faucet service is `infra/build-server/faucet/`. The grant application template is `.forgejo/issue_template/grant.md`. -Served-text rules (the site audit reads every page before it lands): no em dashes, short sentences, one to three points per block, nothing that reads as an offer, a price or a promise of value; devnet and testnet coins have no value; no amount, price or date is promised. +Served-text rules (the site audit reads every page before it lands): no em dashes, short sentences, one to three points per block, nothing that reads as an offer, a price or a promise of value; devnet coins have no value; no amount, price or date is promised. diff --git a/docs/build/build.md b/docs/build/build.md index 64f153607..0e312f2e4 100644 --- a/docs/build/build.md +++ b/docs/build/build.md @@ -4,7 +4,7 @@ This file is the source of [igneum.network/build](https://igneum.network/build). ## What is different -**Every block is built to be proven.** A chain block carries a zero-knowledge proof of its execution. The miners are the provers: the same cards that find blocks prove them, in shards. On Devnet 3 a share of blocks carries a proof today; the live page shows the share and the lag, and the design target at launch is under a minute. Full nodes execute every block themselves, so a bad proof is a light-client problem and never a chain split. +**Every block is built to be proven.** A chain block carries a zero-knowledge proof of its execution. The miners are the provers: the same cards that find blocks prove them, in shards. On the devnet a share of blocks carries a proof today; the live page shows the share and the lag, and the design target at launch is under a minute. Full nodes execute every block themselves, so a bad proof is a light-client problem and never a chain split. **A lock in minutes, not an hour of confirmations.** Miners sign a checkpoint every 30 seconds. When two thirds of the mining weight of the last 30 days have signed, the checkpoint is locked. Weight is blocks mined, nothing else. The lock lands in about two minutes. The [litepaper](/litepaper) has the rule. @@ -14,28 +14,30 @@ This file is the source of [igneum.network/build](https://igneum.network/build). ## Networks -| | Devnet 3 | Testnet | Mainnet | -|---|---|---|---| -| Chain id | {{rm:network.chain_id}} (`{{rm:network.chain_id_hex}}`) since its class v5 floor on 8 October 2026; 4463 below it | 4462 (`0x116e`) | 4461 (`0x116d`) | -| Network id | `{{rm:network.id}}` | `igneum-testnet-1` | not started | -| RPC | `{{rm:network.rpc}}` (a node you run serves `http://127.0.0.1:26790`) | `https://rpc.testnet.igneum.network` (answers; nothing mines there yet, so a transaction waits) | none | -| Coins | no value, resets without notice | no value, resets with notice | not started | -| Symbol, decimals | IGN, 18 | IGN, 18 | IGN, 18 | -| Machine-readable | [/release.json](/release.json): the chain id, the source commits and fingerprints, the mining class, the finality rule, the proof program ids, the fee schedule and the current version per platform, with a generated date | | | +| | Igneum 2.0 devnet | +|---|---| +| Chain id | 4464 (`0x1170`) | +| Network id | `igneum-devnet-4` | +| RPC | `https://rpc.devnet.igneum.network` (a node you run serves `http://127.0.0.1:26790`) | +| Coins | no value, resets without notice | +| Symbol, decimals | IGN, 18 | +| Machine-readable | [/release.json](/release.json): the chain id, the source commits and fingerprints, the mining class, the finality rule, the proof program ids, the fee schedule and the current version per platform, with a generated date | -Devnet 3 is where you build today. It is a developer network: it resets without notice and its coins have no value. Its public RPC takes the read methods, `eth_sendRawTransaction` and a wRPC websocket at `/ws`, at 20 requests a second per address. The public testnet exists, its RPC answers, and no blocks are being produced on it until it opens. Mainnet has no date. Devnet 3 answered 4463 until its class v5 floor at DAA 68,400 on 8 October 2026 and 4464 from it; read it with `eth_chainId` rather than fixing it, since a transaction signed for the wrong id is refused. +The devnet is where you build today. It is a developer network: it resets without notice and its coins have no value. Its public RPC takes the read methods, `eth_sendRawTransaction` and a wRPC websocket at `/ws`, at 20 requests a second per address. Read the chain id with `eth_chainId` rather than fixing it, since a transaction signed for the wrong id is refused. + +Mainnet has not started and has no date. Its chain id, 4461 (`0x116d`), is reserved in the node. ## Endpoints and tools - **Wallet.** Any Ethereum wallet. [Add Igneum to MetaMask](/metamask) with one click, or the [Igneum wallet](/wallet). -- **Faucet.** [10 IGN of Devnet 3 coin](/faucet) per address per day. No account. +- **Faucet.** [10 IGN of the devnet coin](/faucet) per address per day. No account. - **Explorer.** [The explorer](/explorer) shows blocks, the DAG, miners and addresses. The EVM views, transactions and contracts, are being built and link from the same page as they land. -- **Swap.** [The swap](/swap): test tokens on Devnet 3, every swap in a proven block. +- **Swap.** [The swap](/swap): test tokens on the devnet, every swap in a proven block. - **Source.** [git.igneum.network/igneum-network/igneum](https://git.igneum.network/igneum-network/igneum): the node, the miner, the site, and these pages under `docs/build/`. ## Your first contract in five minutes -With [Foundry](https://getfoundry.sh). Tested end to end on Devnet 3 on a build box; the full walkthrough with the expected output is [docs/build/first-contract.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/first-contract.md). +With [Foundry](https://getfoundry.sh). Tested end to end on the devnet on a build box; the full walkthrough with the expected output is [docs/build/first-contract.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/first-contract.md). ``` curl -L https://foundry.paradigm.xyz | bash && foundryup @@ -63,7 +65,7 @@ The call answers `1`. Paste the transaction hash into [the explorer](/explorer). ## The RPC the node serves -Read from a Devnet 3 node, not from a spec. `web3_clientVersion` answers `igneumd/2.1.0/execution-layer-v3`. The full list, served and not served, with the probe that produced it: [docs/build/rpc.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/rpc.md). +Read from a devnet node, not from a spec. `web3_clientVersion` answers `igneumd/2.1.0/execution-layer-v3`. The full list, served and not served, with the probe that produced it: [docs/build/rpc.md](https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/build/rpc.md). - **Served.** `eth_chainId`, `eth_blockNumber`, `eth_getBalance`, `eth_getTransactionCount`, `eth_getCode`, `eth_getStorageAt`, `eth_getBlockByNumber`, `eth_getBlockByHash`, `eth_getTransactionByHash`, `eth_getTransactionReceipt`, `eth_getBlockReceipts`, `eth_getLogs`, `eth_call`, `eth_estimateGas`, `eth_gasPrice`, `eth_maxPriorityFeePerGas`, `eth_feeHistory`, `eth_sendRawTransaction`, `eth_syncing`, `eth_accounts`, `net_version`, `net_peerCount`, `net_listening`, `web3_clientVersion`. - **Igneum's own.** `igneum_getExecStatus`, `igneum_getProvingStatus`, `igneum_getShardPlan`, `igneum_getProofRecords`, `igneum_getTransactionStatus`, `igneum_estimateGas`, `igneum_getBudgets` and the segment and proof calls. `igneum_estimateGas` returns both gas dimensions and whether a call exceeds the proving limit. @@ -86,4 +88,4 @@ console.log(r.verified, r.signers, 'of', r.voters, 'voters', r.ms, 'ms'); - [Discord](https://discord.gg/igneum), the builders channel. - [Grants](/grants) for tooling, reference apps, infrastructure and research. -Devnet and testnet coins have no value. Nothing on this page is an offer to sell anything. +Devnet coins have no value. Nothing on this page is an offer to sell anything. diff --git a/docs/build/faucet.md b/docs/build/faucet.md index d98163047..c346b9ccc 100644 --- a/docs/build/faucet.md +++ b/docs/build/faucet.md @@ -1,11 +1,11 @@ -# The Devnet 3 faucet +# The devnet faucet -[igneum.network/faucet](https://igneum.network/faucet) sends 10 IGN of Devnet 3 coin to an address. Once per address per day, once per connection per day. No account. +[igneum.network/faucet](https://igneum.network/faucet) sends 10 IGN of the devnet coin to an address. Once per address per day, once per connection per day. No account. ## What it is - A small Node service on a build box, `infra/build-server/faucet/faucet.mjs`, behind Caddy at `faucet.igneum.network`. The page on igneum.network posts to it. -- It signs a plain transfer with its own key and sends it to the Devnet 3 node on the same box by address (`FAUCET_RPC`), never chosen by chain id. The chain id it signs with is read from that node on every send: Devnet 3 moved from 4463 to 4464 at its class v5 floor on 8 October 2026. +- It signs a plain transfer with its own key and sends it to the devnet node on the same box by address (`FAUCET_RPC`), never chosen by chain id. The chain id it signs with is read from that node on every send. - The key lives only in the service's environment file on that box. It is not in the repository and not on the site. ## The rules, as the code enforces them @@ -20,7 +20,7 @@ The faucet's balance is refilled from the devnet's funder as it runs down. When it is empty the page says so and sends nothing. -## Devnet 3 coin +## The devnet coin No value. Not for sale, not redeemable, not a claim on anything. The chain resets without notice and balances do not carry over. Mainnet starts from an empty genesis. @@ -33,4 +33,3 @@ infra/build-server/faucet/faucet.sh status # the unit, the balance, the node infra/build-server/faucet/faucet.mjs --self-test # the limiter: known-failed cases first ``` -The public testnet faucet is a separate thing: `site/api/faucet.mjs` is prepared for it and answers "not open yet" until the testnet starts. diff --git a/docs/build/first-contract.md b/docs/build/first-contract.md index afa2c39f7..3acad5e96 100644 --- a/docs/build/first-contract.md +++ b/docs/build/first-contract.md @@ -1,16 +1,16 @@ -# Your first contract on Devnet 3, in five minutes +# Your first contract on the devnet, in five minutes -With Foundry. Tested end to end on Devnet 3 from a build box on 8 October 2026; the pass line and the exact output are at the end. Hardhat, ethers and viem work the same way: chain id 4463 and the RPC below. +With Foundry. Tested end to end on a build box; the pass line and the exact output are at the end. Hardhat, ethers and viem work the same way: chain id 4464 and the RPC below. ## 0. What you need - Foundry: `curl -L https://foundry.paradigm.xyz | bash && foundryup`. About a minute. -- The RPC. Devnet 3's public endpoint is `https://rpc.devnet.igneum.network`. A node you run yourself serves `http://127.0.0.1:26790`. +- The RPC. The devnet's public endpoint is `https://rpc.devnet.igneum.network`. A node you run yourself serves `http://127.0.0.1:26790`. - Nothing else. No account, no sign-up. ``` export RPC=https://rpc.devnet.igneum.network -cast chain-id --rpc-url $RPC # 4464 (4463 before the class v5 floor of 8 October 2026) +cast chain-id --rpc-url $RPC # 4464 ``` ## 1. A key, for the devnet only @@ -82,16 +82,16 @@ cast receipt 0xTXHASH --rpc-url $RPC ## The test record -Run on a build box against its own Devnet 3 node (the box that also fronts the public RPC and runs the faucet), with Foundry 1.8.5 and a fresh key, through `docs/build/first-contract-test.sh`. The pass line is appended below by the run. +Run on a build box against its own devnet node (the box that also fronts the public RPC and runs the faucet), with Foundry 1.8.5 and a fresh key, through `docs/build/first-contract-test.sh`. The pass line is appended below by the run. ``` -PASS 10:17:23Z: Devnet 3 chain id 4463, faucet drip 0x8620e9d894484e824e4ac33002946a00e2f75823ea6db0da0ad29f1af142e8f2, deployed Counter at 0x6345265C6Db0b3713eb6645d795d0B52FE0a4201 (tx 0xcf77b4822d51f3c60ecdf6d7dbbe67524d42071f06c76e1cf9b0511d64783574), increment then setNumber(41) read back 41, receipt status 1 (success), block 27055, 24 s end to end, Foundry 1.8.5 +PASS 10:17:23Z: devnet chain id 4463, faucet drip 0x8620e9d894484e824e4ac33002946a00e2f75823ea6db0da0ad29f1af142e8f2, deployed Counter at 0x6345265C6Db0b3713eb6645d795d0B52FE0a4201 (tx 0xcf77b4822d51f3c60ecdf6d7dbbe67524d42071f06c76e1cf9b0511d64783574), increment then setNumber(41) read back 41, receipt status 1 (success), block 27055, 24 s end to end, Foundry 1.8.5 ``` -Through the public endpoints, `https://rpc.devnet.igneum.network` and `https://faucet.igneum.network`, from the box: the first faucet drip and the first reader-path deploy on Devnet 3. +Through the public endpoints, `https://rpc.devnet.igneum.network` and `https://faucet.igneum.network`, from the box: the first faucet drip and the first reader-path deploy on the devnet. After the class v5 floor moved the chain id to 4464 the same afternoon, from a second box: ``` -PASS 12:38:39Z: Devnet 3 chain id 4464, faucet drip 0xa54fdb7e964dab095aaccaab36ea548fc3fa8727acb809b593c2d4d1359c233f, deployed Counter at 0x7de503a4F39feEBCE8c4ABbAcC04282EE75120Fe (tx 0x6ccdbb4f6393fcf09e58ba2f4de1af98c547eeab6f02d93eacfebae883200dc6), increment then setNumber(41) read back 41, receipt status 1 (success), block 29878, 12 s end to end, Foundry 1.8.5 +PASS 12:38:39Z: devnet chain id 4464, faucet drip 0xa54fdb7e964dab095aaccaab36ea548fc3fa8727acb809b593c2d4d1359c233f, deployed Counter at 0x7de503a4F39feEBCE8c4ABbAcC04282EE75120Fe (tx 0x6ccdbb4f6393fcf09e58ba2f4de1af98c547eeab6f02d93eacfebae883200dc6), increment then setNumber(41) read back 41, receipt status 1 (success), block 29878, 12 s end to end, Foundry 1.8.5 ``` diff --git a/docs/build/grants.md b/docs/build/grants.md index a9d8c5865..c4136d156 100644 --- a/docs/build/grants.md +++ b/docs/build/grants.md @@ -4,7 +4,7 @@ This file is the source of [igneum.network/grants](https://igneum.network/grants ## What a grant is -Grants are paid in IGN from the dev fee fund, on delivery. You propose a piece of work, it is accepted with a written definition of done, you build it, and it runs on the public testnet. Not a salary, not an advance, not an investment. +Grants are paid in IGN from the dev fee fund, on delivery. You propose a piece of work, it is accepted with a written definition of done, you build it, and it runs on the devnet. Not a salary, not an advance, not an investment. The money is the dev fee fund: the IGN that the Ember dev fee collects. Ember, the official miner, takes an optional 1% of a miner's rewards, in full view and off with one flag; that fee goes to Igneum Labs, the company that ships the software. The protocol itself carries no fee, no fund and no allocation, and no grant is paid from emission. [The dev fee](/dev-fee) has the mechanism. @@ -24,7 +24,7 @@ A grant is sized by the work in front of it, not by a table. Two grants in the s Open an issue on [git.igneum.network/igneum-network/igneum](https://git.igneum.network/igneum-network/igneum/issues/new?template=.forgejo%2Fissue_template%2Fgrant.md) and pick the Grant template. It asks for: 1. What you will build, in a paragraph, and which tier it is. -2. What done looks like: what runs where, what a reviewer can click or call to see it working on the public testnet. +2. What done looks like: what runs where, what a reviewer can click or call to see it working on the devnet. 3. Your public work: a repository, a package, a paper, a deployed thing. 4. How you want to be reached. @@ -34,11 +34,11 @@ A short issue is fine. The definition of done is the part that matters. - Every Friday. Each open application gets one of three answers inside seven days: accepted with a definition of done, questions, or no with the reason. - Accepted work is tracked in its issue. The reviewer and the builder agree the definition of done there before any work starts. -- Delivery is reviewed on the public testnet first. Payment follows the review, in the issue, in the open. +- Delivery is reviewed on the devnet. Payment follows the review, in the issue, in the open. ## The honest lines -- Devnet and testnet coins have no value. Before mainnet there is no IGN with value: a grant delivered on the testnet is recorded in its issue, and payment comes from the fund when the fund holds IGN. Nothing is promised about when, or whether, that is. +- Devnet coins have no value. Before mainnet there is no IGN with value: a grant delivered on the devnet is recorded in its issue, and payment comes from the fund when the fund holds IGN. Nothing is promised about when, or whether, that is. - No amount, price or date is promised. The fund is what the dev fee collects, and it is zero today. - A grant is for work delivered, never for a user count, a listing, a post or a referral. - Igneum Labs may decline any application and may close the programme; what has been accepted and delivered is still paid. diff --git a/docs/build/rpc.md b/docs/build/rpc.md index f6dc6d079..d04e2337b 100644 --- a/docs/build/rpc.md +++ b/docs/build/rpc.md @@ -1,6 +1,6 @@ -# The JSON-RPC a Devnet 3 node serves +# The JSON-RPC a devnet node serves -Read from the node, not from a spec: every method below was sent to a Devnet 3 node on 8 October 2026 (`web3_clientVersion` answered `igneumd/2.1.0/execution-layer-v3`, `eth_chainId` `0x116f`, block 26,666) and sorted by what came back. A method the node does not know answers JSON-RPC error `-32601`. The probe is at the end; run it against your own node to refresh this file. +Read from the node, not from a spec: every method below was sent to a devnet node on 8 October 2026 (`web3_clientVersion` answered `igneumd/2.1.0/execution-layer-v3`, `eth_chainId` `0x116f`, block 26,666) and sorted by what came back. A method the node does not know answers JSON-RPC error `-32601`. The probe is at the end; run it against your own node to refresh this file. Transport: HTTP POST, JSON-RPC 2.0, one request per call, no batches tested. The public endpoint is `https://rpc.devnet.igneum.network`; a node you run serves `http://127.0.0.1:26790`. The DAG side of the node (blocks, the mempool, the vote table) speaks the Kaspa-style gRPC and wRPC on their own ports; the explorer and the observer use those, a contract developer needs only what is here. @@ -9,9 +9,9 @@ Transport: HTTP POST, JSON-RPC 2.0, one request per call, no batches tested. The | Method | Note | |---|---| | `web3_clientVersion` | `igneumd//execution-layer-v3` | -| `net_version` | the chain id as a decimal string, `"4464"` (`"4463"` before the class v5 floor) | +| `net_version` | the chain id as a decimal string, `"4464"` | | `net_listening`, `net_peerCount` | | -| `eth_chainId` | `0x1170` (4464) on Devnet 3 since its class v5 floor at DAA 68,400 on 8 October 2026; `0x116f` (4463) below it. Read it, never fix it | +| `eth_chainId` | `0x1170` (4464) on the Igneum 2.0 devnet. Read it, never fix it | | `eth_blockNumber` | the executed chain tip | | `eth_syncing` | `false` when the executor is at the tip | | `eth_mining` | `false` from the RPC's point of view: mining is the miner's, not the node's | @@ -76,4 +76,4 @@ for m in web3_clientVersion eth_chainId eth_blockNumber eth_newFilter eth_subscr done ``` -Devnet 3 resets without notice and its coins have no value. +The devnet resets without notice and its coins have no value. diff --git a/docs/provenance.md b/docs/provenance.md index 2b8fda547..77906d097 100644 --- a/docs/provenance.md +++ b/docs/provenance.md @@ -8,8 +8,8 @@ How to read the licence column. "Verified" means the LICENSE file or the crate's | Component | Origin (project, licence, repository) | What Igneum changed | Why the design needs the change | How the change is measured | |---|---|---|---|---| -| GHOSTDAG ordering | Kaspa, rusty-kaspa. ISC, verified (`vendor/rusty-kaspa/LICENSE`, "Copyright (c) 2022-2024 Kaspa developers"; workspace `license = "ISC"`). https://github.com/kaspanet/rusty-kaspa | Unchanged algorithm. Parameters set for 1 block per second: k 18, 10 max parents, mergeset limit 180, merge depth 3,600 blocks (`consensus/core/src/config/bps.rs`, `params.rs`) | Launch rate is 1 block a second (CLAUDE.md), rising later. These are the values Kaspa mainnet ran before Crescendo, so nothing new is asserted about the ordering | Spec section 2.1; bench-log "igneum-node devnet v0: 3-node igneum-devnet at 1 BPS"; a test in `params.rs` pins every value | -| Node software (the fork) | rusty-kaspa v2.1.0, commit `01b532e8` (22 Sep 2026). ISC, verified. Fork at `vendor/igneum-node`, one commit per change on top of the base | Header gains `vote_key_hash`; genesis blocks; network ids `igneum-*`; devnet ports; DNS seeders emptied; address prefixes; emission schedule and 80/20 coinbase; PoW engine trait; PoW check moved after GHOSTDAG; rename of every user-visible string to `igneumd`. Full list: `docs/fork-divergence.md` | Each row there states the reason. The short version: finality rule v2 needs a vote key in every header, the emission is Igneum's own, the lottery hash needs chain state, and no Igneum node may ever dial a Kaspa peer | `docs/fork-divergence.md` (file, change, why, risk, merge note per row); bench-log devnet v0 and "first devnet blocks on the real lottery hash" entries; the four-node rename test of 3 Oct 2026 | +| GHOSTDAG ordering | Kaspa, rusty-kaspa. ISC, verified (`vendor/rusty-kaspa/LICENSE`, "Copyright (c) 2022-2024 Kaspa developers"; workspace `license = "ISC"`). https://github.com/kaspanet/rusty-kaspa | Unchanged algorithm. Parameters set for 1 block per second: k 18, 10 max parents, mergeset limit 180, merge depth 3,600 blocks (`consensus/core/src/config/bps.rs`, `params.rs`) | Launch rate is 1 block a second (CLAUDE.md), rising later. These are the values Kaspa mainnet ran before Crescendo, so nothing new is asserted about the ordering | Spec section 2.1; the measurement record in the repository (docs/bench-log.md); a test in `params.rs` pins every value | +| Node software (the fork) | rusty-kaspa v2.1.0, commit `01b532e8` (22 Sep 2026). ISC, verified. Fork at `vendor/igneum-node`, one commit per change on top of the base | Header gains `vote_key_hash`; genesis blocks; network ids `igneum-*`; devnet ports; DNS seeders emptied; address prefixes; emission schedule and 80/20 coinbase; PoW engine trait; PoW check moved after GHOSTDAG; rename of every user-visible string to `igneumd`. Full list: `docs/fork-divergence.md` | Each row there states the reason. The short version: finality rule v2 needs a vote key in every header, the emission is Igneum's own, the lottery hash needs chain state, and no Igneum node may ever dial a Kaspa peer | `docs/fork-divergence.md` (file, change, why, risk, merge note per row); the measurement record in the repository (docs/bench-log.md); the four-node rename test of 3 Oct 2026 | | Difficulty controller | Kaspa sampled DAA (KIP-4) in rusty-kaspa, ISC, verified, kept as the retarget. Prior art studied: LWMA by Zawy (zawy12/difficulty-algorithms, licence approximate: MIT) and Monero's sorted and trimmed window (monero-project/monero, approximate: BSD-3-Clause). No code from either | Unchanged in the fork today (comment block only, `consensus/core/src/config/constants.rs`). The hash speed steps at every hourly program change, so a rule that tracks a step within an epoch is in progress: a two-speed rule (fast response to a step, slow drift otherwise). Not in spec 0.1 | Programs differ in cost (35 to 48 Mhash/s across seeds on one GPU), so a 44-minute window spends half an epoch at the wrong block rate | Spec section 2.3 names the two remedies and the gate 2 simpa run that decides; bench-log first-run and RTX 5090 entries hold the per-seed rates. The two-speed rule gets its own bench-log entry when it is simulated | | Random-program idea | RandomX by tevador, Monero. Licence approximate: BSD-3-Clause. https://github.com/tevador/RandomX (not yet cloned under `vendor/`; CLAUDE.md asks for it) | The idea only. Igneum's generator is new code (`igneum-pow/src/generator.rs`): a program drawn once per hourly epoch and compiled to native GPU code, with a per-hash random data path. RandomX draws a program per hash and interprets it on a CPU | A GPU cannot interpret a fresh program per hash at a useful rate; it compiles one program per hour instead. The target hardware is the opposite of RandomX's by design | Spec section 1 (generator, test vectors); bench-log "proto-metal first run", "RTX 5090 first run", "igneum-pow bit-exact" (96/96 vectors, three GPU vendors) | | Memory-hard dataset | RandomX cache lineage (tevador, BSD-3-Clause approximate): a small cache that derives a large dataset by dependent reads | New construction, same shape: 256 MiB cache of chained ChaCha12 blocks, 8 dependent reads per item, dataset 1 GiB in the prototype and 2 GB at genesis, growing on a genesis-fixed schedule (`igneum-pow/src/memhard.rs`, `proto-metal/MEMHARD.md`) | A light verifier must hold only the cache; a miner must hold the dataset; the dataset must outgrow any fixed chip memory. RandomX's dataset has one size for ever | `proto-metal/MEMHARD.md` section 2.2 (recompute 4.8x slower than load, Apple only); bench-log "memory-hard dataset" entries on Metal and the RTX 5090 | @@ -17,11 +17,11 @@ How to read the licence column. "Verified" means the LICENSE file or the crate's | ProgPoW and KAWPOW | ProgPoW (EIP-1057 text, ifdefelse/ProgPOW; KAWPOW on Ravencoin since 2020, RavenProject/Ravencoin, MIT approximate). Prior art, no code used. Not yet cloned; `docs/fud-fixes.md` item 48 asks for the clone and citation before the repository is public | Nothing taken. The difference: ProgPoW and KAWPOW randomise the maths inside a fixed program shape every few blocks; Igneum regenerates the whole program every hour over a growing dataset, with automatic era draws and no human in the loop | Stated so that the "first" claim in the litepaper is accurate (FUD ledger M4) | Litepaper "What has never been done before", row 1, rewritten 3 Oct 2026 | | Class-group VDF | Chia, chiavdf. Apache-2.0, verified (`vendor/chiavdf/LICENSE`), commit `7e62ce14`. Wesolowski's proof (Efficient Verifiable Delay Functions, EUROCRYPT 2019), a paper, no licence | NUDUPL and NUCOMP ported from chiavdf's `qfb_nudupl` and `qfb_nucomp` into `proto-vdf` (Rust, over GMP through `rug`); fresh 1024-bit prime discriminant per input; 256-bit Fiat-Shamir prime (Chia uses 264); Igneum tags for the epoch and era paths. The textbook composition is kept as an oracle | The program seed must come from a certified checkpoint with a delay no miner can skip, so the seed cannot be ground. Chia's group needs no trusted setup | Spec section 4.2 (15,000 random cases agree with the oracle; 163,000 squarings per second; 4.5 ms verify); bench-log "proto-vdf" entry. GMP itself: LGPL-3.0 or GPL-2.0 dual, approximate, prototype only; the production dependency is decided with the wire format (O-4.5) | | revm | Ethereum ecosystem, bluealloy/revm. Licence approximate: MIT. https://github.com/bluealloy/revm (not yet cloned) | Unchanged, credited. Driven by an Igneum block executor that feeds it the DAG's canonical sequence with the environment table of spec 7.1 and two-dimensional gas | The same EVM runs natively and inside the zkVM (reth, rsp and SP1 Reth all use it), so native and proven execution share one code path | `docs/design/execution-layer.md` D6 and section 2.1; differential test plan against reth (section 8.5). Nothing measured yet | -| SP1-class provers | Succinct, succinctlabs/sp1. Licence approximate: MIT or Apache-2.0. Not yet cloned | Unchanged, behind the versioned `ProofSystem` trait (`docs/design/execution-layer.md` 5.6). Version 1 is SP1 (Hypercube class, hash-based). Devnet v1 runs a stub that signs claims | Consumer cards prove hash-based systems without elliptic-curve MSM; the trait makes a swap a release (90% signalling, 3-month overlap, one wrap), never a redesign | No SP1 shard has been proven on any card in this repository (FUD ledger P1, P3). Phase 2 gate: shard time on a 3060-class card, published pass or fail | +| SP1-class provers | Succinct, succinctlabs/sp1. Licence approximate: MIT or Apache-2.0. Not yet cloned | Unchanged, behind the versioned `ProofSystem` trait (`docs/design/execution-layer.md` 5.6). Version 1 is SP1 (Hypercube class, hash-based). An early devnet ran a stub that signs claims | Consumer cards prove hash-based systems without elliptic-curve MSM; the trait makes a swap a release (90% signalling, 3-month overlap, one wrap), never a redesign | No SP1 shard has been proven on any card in this repository (FUD ledger P1, P3). Phase 2 gate: shard time on a 3060-class card, published pass or fail | | BLS12-381 | Curve by Barreto, Lynn and Scott; blst by Supranational. Licence approximate: Apache-2.0. https://github.com/supranational/blst (not yet cloned) | Unchanged, credited. The header carries the BLAKE2b hash of a G1 compressed public key (48 bytes); every voter signs every 30-s checkpoint; signatures aggregate | Finality rule v2 needs one aggregate signature per checkpoint from thousands of keys | Spec section 3.1 (W1) and 2.4; `sim/results_v2.md` for the rule itself. Signature cost not yet measured | | Hashing in the node | rusty-kaspa `crypto/hashes`, ISC, verified. Crates linked by the fork, licences read from the local cargo registry: blake2b_simd 1.0.2 (MIT), blake3 1.8.3 (CC0-1.0 or Apache-2.0), sha2 0.10.8 (MIT or Apache-2.0), keccak 0.1.6 (Apache-2.0 or MIT); sha3 0.10.8 not in the local registry, approximate: MIT or Apache-2.0 | Unchanged, credited. BLAKE2b with domain separation for block, transaction and PoW pre-hashes (`BlockHash`, `TransactionHash`, ...), BLAKE3 keyed for the sequencing-commitment and payload hashers, SHA-256 for ECDSA signing hashes, cSHAKE256 (Keccak) in the kHeavyHash stub that stays as the default engine and for pruning-proof block levels | The chain's hash for everything except the lottery is the one the forked commit uses (spec 0.6), so nothing unverified enters consensus | `hash_override_nonce_time` gained one field (fork-divergence row 1); every header-hash test vector was regenerated and the four genesis hashes re-derived | | Address format | Bitcoin BIP 173 character set (bech32, Pieter Wuille and Greg Maxwell; BIP licence approximate: BSD-2-Clause) with the CashAddr polymod checksum of Bitcoin Cash (the source cites bch.info), as implemented in rusty-kaspa `crypto/addresses/src/bech32.rs`, ISC, verified | Prefixes only: `igneum`, `igneumtest`, `igneumsim`, `igneumdev` (Kaspa: `kaspa`, `kaspatest`, `kaspasim`, `kaspadev`). The script public key behind an address is unchanged | No Igneum address string may parse as a Kaspa address on any network | Fork-divergence row 9; test vectors in `addresses` and `txscript` regenerated and passing | -| The EVM | Ethereum (Yellow Paper and ethereum/execution-specs, CC0 approximate). Cancun opcode set, precompiles 0x01 to 0x09 | Semantics on a DAG: `block.number` is selected-chain height, `block.timestamp` is non-decreasing by a max rule, `prevrandao` is the VDF epoch seed, chain ids 4461, 4462, 4463 (historical: Devnet 3 answers chain id 4464 since its class v5 floor at DAA 68,400 on 8 October 2026, 4463 below it; the current id is in /release.json); 0x0a absent; gas has a second dimension | Blocks on a DAG have no single parent and no header state root; proving cost is a second resource; the random beacon must be unbiasable | Spec section 7.1 (normative table); devnet measurement R9 for timestamp drift; `ethereum/tests` replay in the differential plan | +| The EVM | Ethereum (Yellow Paper and ethereum/execution-specs, CC0 approximate). Cancun opcode set, precompiles 0x01 to 0x09 | Semantics on a DAG: `block.number` is selected-chain height, `block.timestamp` is non-decreasing by a max rule, `prevrandao` is the VDF epoch seed, chain id 4464 on the devnet and 4461 reserved for mainnet (the current id is in /release.json); 0x0a absent; gas has a second dimension | Blocks on a DAG have no single parent and no header state root; proving cost is a second resource; the random beacon must be unbiasable | Spec section 7.1 (normative table); devnet measurement R9 for timestamp drift; `ethereum/tests` replay in the differential plan | | kHeavyHash (kept as a stub) | Kaspa, rusty-kaspa `crypto/hashes/src/pow_hashers.rs` and `consensus/pow/src/matrix.rs`, ISC, verified | Kept untouched as `HeavyHashEngine`, the default engine when the `igneum-pow` feature is off, and the block-level source for pruning proofs until seeds are threaded through | Lets the devnet run and lets upstream pow changes merge cleanly | Fork-divergence rows 14 and 15; open item in the same file (pruning-proof block levels) | ## What is new in Igneum @@ -30,7 +30,7 @@ Nothing here has a precedent that Igneum could have copied. Each item names the | Piece | What it is | Where it is specified or measured | |---|---|---| -| The hourly header-bound GPU program | A program drawn per epoch from a VDF seed, compiled to native GPU code, with the nonce-zeroed header hash absorbed into the init words so one nonce serves one header | Spec section 1 and `igneum-pow/src/bind.rs`; bench-log "first devnet blocks on the real lottery hash" | +| The hourly header-bound GPU program | A program drawn per epoch from a VDF seed, compiled to native GPU code, with the nonce-zeroed header hash absorbed into the init words so one nonce serves one header | Spec section 1 and `igneum-pow/src/bind.rs`; the measurement record in the repository (docs/bench-log.md) | | Sustained-mining finality, rule v2 | Vote weight is blue blocks per BLS vote key over a flat 30-day window; every voter signs every 30-s checkpoint; lock at 2/3 of active weight and at least 56.7% of total weight; no stake, no other chain | Spec section 3; `sim/results_v2.md` (0 conflicting locks in every partition and eclipse scenario) | | Two-dimensional gas and the per-frame app share | Execution gas on Ethereum's schedule plus proving gas from a calibrated table; 20% of the priority fee attributed per call frame to the registered developer of the contract that ran | Spec sections 5.1, 5.2; `docs/design/execution-layer.md` section 4 | | The shard market and the native proving precompile | Shards cut from the native trace, assigned by sortition to 8 eligible provers for 10 s, then open; a `Prover` system contract that takes a job and returns the result by a later proof record | Spec section 7.2; `docs/design/execution-layer.md` sections 5 and 6 | diff --git a/site/404.html b/site/404.html index 90993fbd8..de511b685 100644 --- a/site/404.html +++ b/site/404.html @@ -4,7 +4,7 @@ Page not found. Igneum - + @@ -77,7 +77,7 @@ main{flex:1} IGNEUM - devnet + Igneum 2.0 devnet starting @@ -150,12 +148,10 @@ main{flex:1}
Learn
LitepaperThe design, as published. @@ -169,7 +165,7 @@ main{flex:1}
@@ -234,7 +230,6 @@ main{flex:1}
  • The minerOne click, and your card mines
  • LitepaperHow the chain works, in 19 sections
  • Live devnetBlocks, miners and finality as they happen
  • -
  • Engineering logEvery measurement, with the commands
  • EvidenceEvery claim and how far it is tested
  • @@ -242,6 +237,7 @@ main{flex:1}
    @@ -259,9 +255,9 @@
    Overview · Mac
    - The Overview page of 0.3.22 on an Apple M5 Max: 17.0 MH/s, 6,784 blocks this run, the ladder strip with signing under way, the chain drawn live with this Mac's blocks ringed, the node synced with 4 peers - The Overview page of 0.3.22 in light mode on an Apple M5 Max: 17.0 MH/s, the ladder strip, the chain drawn live -
    0.3.22, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    + The Overview page of the current build on an Apple M5 Max: 17.0 MH/s, 6,784 blocks this run, the ladder strip with signing under way, the chain drawn live with this Mac's blocks ringed, the node synced with 4 peers + The Overview page of the current build in light mode on an Apple M5 Max: 17.0 MH/s, the ladder strip, the chain drawn live +
    The current build, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    01 · Overview
    @@ -282,9 +278,9 @@
    Cards
    - The Cards page of 0.3.22: Ember Tune with the Efficiency, Balanced and Maximum goals; one row per card with its vendor's mark, its series line, its rate, IGN a day, watts, hashes per watt, cost a day and temperature: an RTX 5090 at 122 MH/s and 291 W, an RX 9070 XT at 18.9 MH/s and 198 W, an Arc B580 at 15.2 MH/s, an integrated UHD 770 off - The Cards page of 0.3.22 in light mode: Ember Tune and the four card rows with their vendor marks, the RTX 5090 at 122 MH/s and 291 W -
    0.3.22, rendered from the app’s recorded states, 7 October 2026: a mixed rig of an RTX 5090, an RX 9070 XT, an Arc B580 and an integrated UHD 770. The 5090 and the 9070 XT carry measured rates; the Arc’s 15.2 MH/s is the plan’s expectation until the measurement on the team's three-card Windows rig lands. Each row carries its vendor’s mark and its series line.
    + The Cards page of the current build: Ember Tune with the Efficiency, Balanced and Maximum goals; one row per card with its vendor's mark, its series line, its rate, IGN a day, watts, hashes per watt, cost a day and temperature: an RTX 5090 at 122 MH/s and 291 W, an RX 9070 XT at 18.9 MH/s and 198 W, an Arc B580 at 15.2 MH/s, an integrated UHD 770 off + The Cards page of the current build in light mode: Ember Tune and the four card rows with their vendor marks, the RTX 5090 at 122 MH/s and 291 W +
    The current build, rendered from the app’s recorded states, 7 October 2026: a mixed rig of an RTX 5090, an RX 9070 XT, an Arc B580 and an integrated UHD 770. The 5090 and the 9070 XT carry measured rates; the Arc’s 15.2 MH/s is the plan’s expectation until the measurement on the team's three-card Windows rig lands. Each row carries its vendor’s mark and its series line.
    02 · Cards
    @@ -304,7 +300,7 @@ RTX 4070106.0 W · 28.72 MH/s · 0.271 MH/W75.6 W · 28.78 MH/s · 0.381 MH/W30 W, £0.20 a day at 28p/kWh
    -

    Ember run 6 on the three-card Windows rig. The pounds are arithmetic from the saved watts at 28p per kWh; the app uses your price. The log.

    +

    Ember run 6 on the three-card Windows rig. The pounds are arithmetic from the saved watts at 28p per kWh; the app uses your price. Details are in the measurement record in the repository (docs/bench-log.md).

    @@ -339,9 +335,9 @@
    Earnings
    - The Earnings page of 0.3.22: 29,517 IGN a day at the last hour's rate with the reason line, 6,784 blocks this run with their IGN, then weight rank 3 of 4 keys, electricity with no draw reported on Apple silicon, 8,054 blocks lifetime, the dev fee switch, and the ladder card under it - The Earnings page of 0.3.22 in light mode: IGN a day first, then blocks this run, weight, electricity and lifetime -
    0.3.22, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026. IGN a day first, then blocks this run, then weight, electricity and lifetime; no price of IGN anywhere.
    + The Earnings page of the current build: 29,517 IGN a day at the last hour's rate with the reason line, 6,784 blocks this run with their IGN, then weight rank 3 of 4 keys, electricity with no draw reported on Apple silicon, 8,054 blocks lifetime, the dev fee switch, and the ladder card under it + The Earnings page of the current build in light mode: IGN a day first, then blocks this run, weight, electricity and lifetime +
    The current build, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026. IGN a day first, then blocks this run, then weight, electricity and lifetime; no price of IGN anywhere.
    04 · Earnings
    @@ -362,9 +358,9 @@
    Prove
    - The Prove page of 0.3.22: the shard card, your card proved shard 3 of block 160,390 for 1.15 IGN; the Prove on this machine switch on, one sentence for the Apple M5 Max, which proves on the CPU slowly; one line of counts, and Details - The Prove page of 0.3.22 in light mode: the shard card and the Prove on this machine switch -
    0.3.22, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026. Apple silicon proves on the CPU, slowly; a 12 GB NVIDIA card is the line for proving beside the miner.
    + The Prove page of the current build: the shard card, your card proved shard 3 of block 160,390 for 1.15 IGN; the Prove on this machine switch on, one sentence for the Apple M5 Max, which proves on the CPU slowly; one line of counts, and Details + The Prove page of the current build in light mode: the shard card and the Prove on this machine switch +
    The current build, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026. Apple silicon proves on the CPU, slowly; a 12 GB NVIDIA card is the line for proving beside the miner.
    05 · Prove
    @@ -387,9 +383,9 @@
    Settings · Tuning
    - The Settings page of 0.3.22 from the top: the Tuning card with the goal at Balanced and the Ember Tune and Power control switches, each with one sentence, then Electricity with the region, the currency and the price per kWh - The Settings page of 0.3.22 in light mode: the Tuning card and Electricity -
    0.3.22, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    + The Settings page of the current build from the top: the Tuning card with the goal at Balanced and the Ember Tune and Power control switches, each with one sentence, then Electricity with the region, the currency and the price per kWh + The Settings page of the current build in light mode: the Tuning card and Electricity +
    The current build, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    • Electricity pricePence per kWh, set once. Every pound figure in the app uses it.
    • @@ -410,15 +406,15 @@
    390 px
    - The Overview page of 0.3.22 in a 390 pixel wide window: the rate, the Stop mining button, the chain live, and a bottom tab bar with Overview, Cards, Earnings, Prove, Settings and Logs - The Overview page of 0.3.22 in a 390 pixel wide window, light mode: 17.0 MH/s, the Stop mining button, the chain live and the bottom tab bar -
    0.3.22, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    + The Overview page of the current build in a 390 pixel wide window: the rate, the Stop mining button, the chain live, and a bottom tab bar with Overview, Cards, Earnings, Prove, Settings and Logs + The Overview page of the current build in a 390 pixel wide window, light mode: 17.0 MH/s, the Stop mining button, the chain live and the bottom tab bar +
    The current build, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    390 px
    - The Cards page of 0.3.22 in a 390 pixel wide window: Ember Tune and the card rows stacked with their vendor marks, with the bottom tab bar - The Cards page of 0.3.22 in a 390 pixel wide window, light mode: Ember Tune, the card rows and the bottom tab bar -
    0.3.22, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    + The Cards page of the current build in a 390 pixel wide window: Ember Tune and the card rows stacked with their vendor marks, with the bottom tab bar + The Cards page of the current build in a 390 pixel wide window, light mode: Ember Tune, the card rows and the bottom tab bar +
    The current build, rendered from the recorded state of the team’s Apple M5 Max, 7 October 2026.
    @@ -429,7 +425,7 @@
    08 · It keeps mining

    Built to be left alone

    -

    Measured against a worker that misbehaves on command, 4 October 2026: recoveries in seconds. The log.

    +

    Measured against a worker that misbehaves on command, 4 October 2026: recoveries in seconds. Details are in the measurement record in the repository (docs/bench-log.md).

    • Hourly program, no pauseThe next program compiles in the background and swaps at the boundary: 0.01 ms on Metal, 0.00 ms on CUDA, 0 rejected blocks.
    • @@ -457,7 +453,6 @@

    Your card: pending

    -

    Public testnet: not yet open; the devnet build is here for people who want to look.

    Devnet. Coins have no value and the chain may be reset.

    @@ -480,6 +475,7 @@