litepaper: the conceded ledger items worded honestly (M2, M4, M7, M9, M13, F5, F10, P1, P4, P6, P7, P10, E5, G1, G2, G4, G6, C2, C3, C5, C6, C8, C10, C11, M18, X1, X7, X8, X9)
Precedents table replaces the firsts table, with state and sources; labels Measured, Implemented, Designed, Target, Open where the ledger asks; one Who paragraph; no listings; private repository until the public testnet; issues route. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
0f29fa4969
commit
f6791fdc25
1 changed files with 63 additions and 56 deletions
|
|
@ -256,12 +256,13 @@ body.all .pager{display:none}
|
|||
<div>
|
||||
<div class="eyebrow">Litepaper · version 0.2</div>
|
||||
<h1>Mined by GPUs.<br>Proven by fire.</h1>
|
||||
<div class="tag">A proof-of-work chain whose miners also prove every block, run Ethereum's apps, and built so no chip can ever take your place.</div>
|
||||
<div class="tag">A proof-of-work chain whose miners also prove every block, run Ethereum's apps, and are protected from specialised chips by a program that changes every hour.</div>
|
||||
</div>
|
||||
<div class="meta">
|
||||
<span>Published <b>3 October 2026</b> · updated <b>5 October 2026</b></span>
|
||||
<span>Coin <b>IGN</b> · cap <b>4,000,000,000</b></span>
|
||||
<span>Status <b>devnet live, pre-testnet</b></span>
|
||||
<span>Method <b>one founder with AI systems</b> · external review before gate 3</span>
|
||||
<span>This is not an offer to sell anything</span>
|
||||
</div>
|
||||
</header>
|
||||
|
|
@ -270,7 +271,7 @@ body.all .pager{display:none}
|
|||
<nav class="toc" aria-label="Contents">
|
||||
<ol>
|
||||
<li><a href="#abstract">Abstract</a></li>
|
||||
<li><a href="#firsts">What has never been done</a></li>
|
||||
<li><a href="#firsts">Precedents, and what Igneum adds</a></li>
|
||||
<li><a href="#problem">The problem</a></li>
|
||||
<li><a href="#glance">Igneum at a glance</a></li>
|
||||
<li><a href="#mining">Mining</a></li>
|
||||
|
|
@ -297,7 +298,7 @@ body.all .pager{display:none}
|
|||
<section id="abstract">
|
||||
<h2>Abstract</h2>
|
||||
<p class="lead">Igneum is a proof-of-work blockchain mined on graphics cards, where the same cards prove every block with zero-knowledge proofs and sell proving to other chains.</p>
|
||||
<p>It runs the Ethereum virtual machine, so anything built for Ethereum runs on Igneum unchanged. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two. There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining stays open to anyone with a GPU because the mining program itself changes every hour, so there is nothing for a specialised chip to be built for. Nothing in it ever needs a human to keep it that way.</p>
|
||||
<p>It runs the Ethereum virtual machine, so anything built for Ethereum runs on Igneum unchanged. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two. There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining stays open to anyone with a GPU because the mining program changes every hour, so a chip built for one program is useless for the next, and a chip for the whole program space is a GPU without the graphics parts. No scheduled human release is needed to keep it that way. Writing new code, including an emergency fix to the proof system, is the one thing that takes a person, and it activates only on miner signalling.</p>
|
||||
<div class="stats">
|
||||
<div class="stat"><div class="v">1 / s</div><div class="k">blocks, rising to 10</div></div>
|
||||
<div class="stat"><div class="v">~60 s</div><div class="k">to a proof at launch</div></div>
|
||||
|
|
@ -307,32 +308,33 @@ body.all .pager{display:none}
|
|||
</section>
|
||||
|
||||
<section id="firsts">
|
||||
<h2>What has never been done before</h2>
|
||||
<p>Every piece of Igneum has a precedent somewhere. The combination has none, and six of the pieces are firsts on their own.</p>
|
||||
<h2>Precedents, and what Igneum adds</h2>
|
||||
<p>Every piece of Igneum has a precedent somewhere. We know of no chain that combines them. The table names the closest precedent for each piece, what Igneum adds, and how far each piece has got. It will be corrected when shown wrong.</p>
|
||||
<div class="tbl"><table>
|
||||
<thead><tr><th>First</th><th>Closest precedent</th><th>What Igneum adds</th></tr></thead>
|
||||
<thead><tr><th>Piece</th><th>Closest precedent</th><th>What Igneum adds</th><th>State, 5 Oct 2026</th></tr></thead>
|
||||
<tbody>
|
||||
<tr><td>A mining program that regenerates itself, for GPUs</td><td>RandomX does it for CPUs on Monero, since 2019</td><td>Whole-program regeneration on GPUs. ProgPoW and Ravencoin's KAWPOW randomised the maths inside a fixed program shape in 2020; Igneum regenerates the whole program hourly over a growing dataset, with automatic eras</td></tr>
|
||||
<tr><td>The mining card does paid, useful, verifiable work</td><td>Primecoin's prime chains in 2013 were not useful. Aleo's proving-as-consensus centralised</td><td>Proving is useful, verifiable in milliseconds, and kept apart from the lottery</td></tr>
|
||||
<tr><td>A proof-of-work chain where every block is proven</td><td>zkEVMs exist only as rollups on proof-of-stake Ethereum. Conflux has run GPU-mined EVM apps on a DAG since 2020, without proofs</td><td>Proven state on a proof-of-work base layer, produced by the miners themselves</td></tr>
|
||||
<tr><td>Finality held by miners and immune to hour-long rentals</td><td>Decred votes with stake. Horizen penalises hidden chains. Kaspa limits depth</td><td>Sustained-mining weight: hashrate that appeared today has no vote</td></tr>
|
||||
<tr><td>100% of emission to the people running the hardware</td><td>Kaspa's fair launch, with no utility. Zcash and Decred fund developers from emission</td><td>Fair launch, utility, and no fee to any team, foundation or fund</td></tr>
|
||||
<tr><td>A chain your browser verifies by itself</td><td>Light clients trust a committee</td><td>At launch, one execution proof plus the votes on the latest locked checkpoint. The single-proof client that also proves canonicity is phase two and the roadmap says so</td></tr>
|
||||
<tr><td>A mining program that regenerates itself, for GPUs</td><td>RandomX on Monero since 2019, for CPUs, a program per hash. ProgPoW, as KAWPOW on Ravencoin since 2020, changes the maths inside a fixed program shape every few blocks on GPUs (approximate)</td><td>A whole kernel per hour compiled to native code, a daily dataset from a 256 MB cache, a verifiable delay before the seed, era draws from a genesis reserve</td><td>Measured: hourly swaps on Apple, NVIDIA and AMD cards on the live devnet, 4 October 2026</td></tr>
|
||||
<tr><td>The mining card does paid, useful, verifiable work</td><td>Primecoin's prime chains in 2013 were not useful. Aleo ran proving as consensus and the fastest prover won (both approximate)</td><td>Proving kept apart from the lottery; shards assigned by sortition, not by speed</td><td>Implemented: proving v0 on the live devnet since 5 October 2026. The job market for other chains is Designed</td></tr>
|
||||
<tr><td>A proof-of-work chain where every block is proven</td><td>zkEVMs run as rollups on proof-of-stake Ethereum. Conflux has run GPU-mined EVM apps on a DAG since 2020, without proofs (approximate)</td><td>Proven state on a proof-of-work base layer, produced by the miners themselves</td><td>Implemented in part: shards proven and paid on the devnet. The aggregated block proof checked in consensus is Designed</td></tr>
|
||||
<tr><td>Finality held by miners and not moved by hour-long rentals</td><td>Decred votes with stake. Horizen penalises hidden chains. Kaspa limits merge depth (approximate)</td><td>Vote weight is 30 days of blocks per key. Hashrate that appeared today has no vote</td><td>Implemented: rule v2 live on the devnet, first lock 4 October 2026. External review is owed at gate 3</td></tr>
|
||||
<tr><td>100% of emission to the people running the hardware</td><td>Kaspa's fair launch. Zcash and Decred fund developers from emission (approximate)</td><td>No fee to any team, foundation or fund in the protocol. The miner software's optional 1% dev fee is the one payment to the project, off with one flag</td><td>Implemented in consensus: the 80/20 coinbase on the devnet</td></tr>
|
||||
<tr><td>A chain your browser verifies by itself</td><td>Light clients trust a committee, as Ethereum's trust a sync committee (approximate)</td><td>At launch, one execution proof plus a certificate the client is given. The consensus proof that makes the checkpoint self-verifying is phase two</td><td>Designed. The home page's card verifies a devnet certificate in the browser today, with the voter list taken from a node</td></tr>
|
||||
</tbody>
|
||||
</table></div>
|
||||
<div class="pull">GPU mining lost its home in 2022. Igneum is the first chain built so that it can never be taken away again: not by a chip, not by a merge to proof of stake, not by a rental attack, and not by a foundation.</div>
|
||||
<p class="src"><b>Sources:</b> the engineering log for every Measured and Implemented cell; the provenance table in the repository for what was taken from each project and under which licence. Claims about other chains are from memory until cited from their repositories and are marked approximate.</p>
|
||||
<div class="pull">GPU mining lost its largest home in 2022. Igneum is built to make it hard to take away: by a chip, by a merge to proof of stake, by a rental attack, or by a foundation.</div>
|
||||
</section>
|
||||
|
||||
<section id="problem">
|
||||
<h2>The problem</h2>
|
||||
<p>Three things are wrong at once, and Igneum is built where they meet.</p>
|
||||
<h3>GPU mining has no home</h3>
|
||||
<p>Ethereum left proof of work in 2022 and stranded the largest fleet of general-purpose compute ever assembled. Every chain that took it in since has either been taken over by chips, as Kaspa was within about two years, or has stayed small, as Ergo and Ravencoin have. Miners burn electricity on a lottery and are paid in inflation. When the price falls they switch off, and the chain's security goes with them.</p>
|
||||
<p>Ethereum left proof of work in 2022 and stranded the largest fleet of general-purpose compute ever assembled. Since then the GPU chains have gone two ways. Chips arrived, as on Kaspa, whose hash was designed to welcome them. Or the chain stayed small: Ergo, Ravencoin and Conflux still mine on GPUs at a fraction of the 2022 fleet (approximate). Miners burn electricity on a lottery and are paid in inflation. When the price falls they switch off, and the chain's security goes with them.</p>
|
||||
<h3>Proving is centralised</h3>
|
||||
<p>Rollups, bridges and soon Ethereum itself need zero-knowledge proofs of every batch and every block. Today those proofs come from a few private GPU clusters run by the rollup teams or by a handful of proving companies. The work is a commodity, a proof is correct or it is not, and the cheapest correct proof should win. It does not, because the people with the cheapest GPUs are not in the market.</p>
|
||||
<h3>Small proof-of-work chains get attacked</h3>
|
||||
<p>When rental markets can hire more hashrate than a chain has for an hour, double-spends against exchanges are cheap. Ethereum Classic, Bitcoin Gold and Vertcoin were all hit this way. Every one of them let hashrate that appeared a minute ago rewrite history.</p>
|
||||
<p>Igneum gives the GPU fleet paid, useful, verifiable work. It gives the proving market its cheapest supplier. And it makes the right to rewrite history something that must be earned over a month of public mining, not rented for an hour.</p>
|
||||
<p>Igneum gives the GPU fleet paid, useful, verifiable work. It gives the proving market a supplier whose marginal cost is close to power. And it makes the right to rewrite history something that must be earned over a month of public mining, not rented for an hour.</p>
|
||||
</section>
|
||||
|
||||
<section id="glance">
|
||||
|
|
@ -348,7 +350,7 @@ body.all .pager{display:none}
|
|||
<rect x="50" y="48" width="400" height="72" rx="8" fill="var(--surface)" stroke="var(--line)" stroke-width="1.25"></rect>
|
||||
<text x="66" y="72" font-size="13" font-weight="600" fill="var(--ink)">1. Mining lottery</text>
|
||||
<text x="66" y="90" fill="var(--ink)">A random GPU program picks who makes the next block</text>
|
||||
<text x="66" y="106" fill="var(--quiet)">New program every hour, so only a GPU runs it well</text>
|
||||
<text x="66" y="106" fill="var(--quiet)">New program every hour, so a chip for last hour's program is useless</text>
|
||||
</g>
|
||||
<g>
|
||||
<rect x="50" y="152" width="400" height="72" rx="8" fill="var(--surface)" stroke="var(--line)" stroke-width="1.25"></rect>
|
||||
|
|
@ -405,19 +407,20 @@ body.all .pager{display:none}
|
|||
<section id="mining">
|
||||
<h2>Mining: a program that never holds still</h2>
|
||||
<p>Every GPU chain that promised ASIC resistance shipped a fixed algorithm, and a fixed algorithm gets a chip the moment the prize pays for one. Igneum does not have a fixed algorithm.</p>
|
||||
<p>Each hour the chain derives a seed from a locked checkpoint one epoch back, passes it through a ten-minute verifiable delay so no miner can see which program a seed implies before choosing whether to publish a block, and feeds it to a deterministic generator. The generator emits a random integer program built from what graphics cards are uniquely good at: wide parallel integer maths, shuffles between the 32 lanes of a warp, and random reads over a multi-gigabyte dataset that changes daily, so the program is bound by memory bandwidth. The memory footprint and instruction count are fixed and only the maths sequence is random, so no hour favours one vendor's cards and nobody gains by grinding the seed. Miners compile the program once per hour. Anyone running a node, a wallet or an exchange checks a hash on an ordinary CPU in about ten milliseconds by simulating one warp, so nobody needs a GPU except to mine.</p>
|
||||
<p>Each hour the chain derives a seed from a locked checkpoint one epoch back, passes it through a ten-minute verifiable delay so no miner can see which program a seed implies before choosing whether to publish a block, and feeds it to a deterministic generator. The generator emits a random integer program built from what graphics cards are uniquely good at: wide parallel integer maths, shuffles between the 32 lanes of a warp, and random reads over a multi-gigabyte dataset that changes daily, so the program is bound by memory bandwidth. The memory footprint and instruction count are fixed and only the maths sequence is random, so no hour favours one vendor's cards and nobody gains by grinding the seed. Miners compile the program once per hour. Anyone running a node, a wallet or an exchange checks a hash on an ordinary CPU in under ten milliseconds by simulating one warp, so nobody needs a GPU except to mine. Measured: 0.41 to 0.58 ms per warp on one Apple M5 Max core with the 256 MB cache, about 17x inside the 10 ms gate; a 2019-class laptop core is not yet measured.</p>
|
||||
<p>The hash is a lottery, not a general-purpose cryptographic hash. It has to be unpredictable per nonce, free of any shortcut cheaper than honest evaluation, and free of bias a miner can exploit. It does not need preimage or collision resistance. Open: no analysis of the lottery properties exists yet. It is the first job of the external review in phase 1, and until then the hash is a design claim backed by the measurements below.</p>
|
||||
<div class="tbl"><table>
|
||||
<thead><tr><th>Clock</th><th>What changes</th><th>Miner update needed?</th></tr></thead>
|
||||
<tbody>
|
||||
<tr><td>Every hash</td><td>The data path depends on the nonce, so no two hashes run the same sequence</td><td>No</td></tr>
|
||||
<tr><td>Every hash</td><td>The 128 dataset addresses depend on the nonce, so every hash reads different memory. The one-bit select inside the maths costs a chip nothing and is not a defence; the random reads are</td><td>No</td></tr>
|
||||
<tr><td>Every hour</td><td>A new random program</td><td>No, the miner compiles whatever arrives</td></tr>
|
||||
<tr><td>Every day</td><td>A new dataset</td><td>No</td></tr>
|
||||
<tr><td>Every six months</td><td>A new instruction mix and memory pattern drawn by the chain from rules fixed at genesis, and a new family of instructions unlocked from a reserve written at genesis, so the program space widens every era</td><td>No</td></tr>
|
||||
<tr><td>Continuously</td><td>The dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. A chip is built with fixed memory, so it is on a countdown from the day it ships. Ethereum's growing dataset killed Bitmain's E3 miner in 2020 this way, with nobody doing anything</td><td>No</td></tr>
|
||||
<tr><td>Continuously</td><td>The dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. A chip is built with fixed memory, so it is on a countdown from the day it ships. Ethereum's growing dataset ran Bitmain's E3 out of memory in 2020 this way, approximate, with nobody doing anything</td><td>No</td></tr>
|
||||
</tbody>
|
||||
</table></div>
|
||||
<p>Everything above is automatic. Nobody writes a new program, nobody schedules a fork, and Igneum runs for ever on the generator fixed at genesis, exactly as Monero has run on RandomX since 2019 with no chip built. The generator is designed so that the best hardware for any program it can emit is a graphics card. A chip that dropped the graphics parts and kept the parallel cores and the memory would gain under 2x, approximate, which is below what pays for a tapeout, and that is the same margin that has protected Monero for seven years. On top of that, the widening program space and the growing dataset mean a chip designed for this year's Igneum meets a harder Igneum next year without anyone lifting a finger.</p>
|
||||
<p>One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built so that day never comes, and it does not depend on it.</p>
|
||||
<p>Everything above is automatic. Nobody writes a new program, nobody schedules a fork, and Igneum runs on the generator fixed at genesis, as Monero has run on RandomX since 2019 with no chip publicly shipped, approximate. Monero is precedent, not proof: absence of a public chip does not show that none can exist, which is why a bounty exists. The generator is designed so that the best hardware for any program it can emit is a graphics card. Target: a chip that dropped the graphics parts and kept the parallel cores and the memory gains under 2x, below what pays for a tapeout. That is a design target, not a measurement. Ethash chips reached roughly 1.5 to 2x, approximate, and the standing bounty exists to test the target. On top of that, the widening program space and the growing dataset mean a chip designed for this year's Igneum meets a harder Igneum next year without anyone lifting a finger.</p>
|
||||
<p>One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.</p>
|
||||
</section>
|
||||
|
||||
<section id="randomx">
|
||||
|
|
@ -427,37 +430,37 @@ body.all .pager{display:none}
|
|||
<thead><tr><th>Property</th><th>RandomX, Monero</th><th>Igneum</th></tr></thead>
|
||||
<tbody>
|
||||
<tr><td>Hardware it is built for</td><td>CPUs. GPUs run it badly on purpose</td><td>GPUs. Any card, any vendor. Bit-exact on Apple, NVIDIA and AMD, measured</td></tr>
|
||||
<tr><td>Random program</td><td>Per hash, interpreted in a virtual machine</td><td>Per hour, compiled to native GPU code, with a per-hash random data path</td></tr>
|
||||
<tr><td>Random program</td><td>Per hash, interpreted in a virtual machine</td><td>Per hour, compiled to native GPU code. Per hash, the 128 dataset addresses change with the nonce</td></tr>
|
||||
<tr><td>Dataset</td><td>About 2 GB, the same size since 2019, approximate</td><td>2 GB at genesis, growing every year past any chip's memory</td></tr>
|
||||
<tr><td>Light verification</td><td>256 MB cache on a CPU, milliseconds</td><td>256 MB cache on a CPU, one warp under 10 ms, the measured gate</td></tr>
|
||||
<tr><td>Light verification</td><td>256 MB cache on a CPU, milliseconds</td><td>256 MB cache on a CPU, one warp under 10 ms, the gate. Measured 0.41 to 0.58 ms on one Apple M5 Max core; a 2019-class core not yet</td></tr>
|
||||
<tr><td>Changes over time</td><td>None. A fixed design, unchanged for seven years</td><td>Automatic era draws and a reserve of instruction families that unlock by height. Nobody touches it</td></tr>
|
||||
<tr><td>Seed grinding</td><td>Not applicable, the program comes from the hash input</td><td>Closed by a verifiable delay between seed and program</td></tr>
|
||||
<tr><td>Useful work</td><td>None. Hashing only</td><td>The same card proves every block and sells proofs to other chains</td></tr>
|
||||
<tr><td>Track record</td><td>No chip in seven years</td><td>Zero years. Every number above is measured and logged with the commands that produced it, and the specification, reference hash, test vectors and simulators are public now (github.com/igneum-network/spec); the node opens with the public benchmark in January 2027</td></tr>
|
||||
<tr><td>Track record</td><td>No chip publicly shipped in seven years, approximate</td><td>Zero years. Every number above is measured and logged with the commands that produced it. The specification, reference hash, test vectors and simulators are public now (github.com/igneum-network/spec). The node, the miner and the wallet are in a private repository until the public testnet</td></tr>
|
||||
</tbody>
|
||||
</table></div>
|
||||
<p>Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Those are prototype figures: the prototype's dataset is still a simple formula a miner could compute instead of loading, which the next build replaces with a 256 MB cache construction, so the rates will change and are not mining rates. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. On 4 October 2026 the live devnet crossed an hourly program change on all three vendors with no pause and no rejected block: a Mac at 26.7 million hashes a second, an RTX 5090 at 123 million and an integrated AMD chip at 2.7 million, every hash doing 128 distinct reads of the memory-hard dataset.</p>
|
||||
<p>Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Those are prototype figures, not mining rates. The first prototype dataset was a closed-form function, and a miner could compute items instead of loading them: measured 111x faster that way on the Mac. The 256 MB cache construction replaced it on 3 October 2026. With the cache, computing items on the fly runs 4.8x slower than loading them, measured on the Mac, and the honest rate is unchanged on both vendors. Open: the same shortcut ratio on NVIDIA and on a discrete AMD card, and the time-memory trade-off between the two measured points. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. On 4 October 2026 the live devnet crossed an hourly program change on all three vendors with no pause and no rejected block: a Mac at 26.7 million hashes a second, an RTX 5090 at 123 million and an integrated AMD chip at 2.7 million, every hash doing 128 distinct reads of the memory-hard dataset.</p>
|
||||
</section>
|
||||
|
||||
<section id="proving">
|
||||
<h2>Proving: the miners are the provers</h2>
|
||||
<p>Every Igneum block is proven with a zero-knowledge proof, and the miners produce it. Proving is the one useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not, and a phone can check it in milliseconds.</p>
|
||||
<p>Every Igneum block is proven with a zero-knowledge proof, and the miners produce it. Proving is a useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not, and a phone can check it in milliseconds.</p>
|
||||
<h3>How a block gets proven</h3>
|
||||
<p>Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond. Provers run them on consumer cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch. Because the proof computes the state from the ordered sequence, a block with a wrong state cannot exist. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.</p>
|
||||
<p>Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond. Provers run them on consumer cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch. Because the proof computes the state from the ordered sequence, no node accepts a block with a wrong state root. Full nodes also execute every block natively and reject a proof record whose result differs from their own execution, so a forged proof is a light-client problem and never a chain split. Implemented: the native-execution check on every carried proof record, proving v0 on the devnet (specification section 7). The emergency path for a soundness bug in the proof system is a human one: a new proof-system version is written by people and activates only on miner signalling. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.</p>
|
||||
<h3>The proving budget</h3>
|
||||
<p>Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Shard size will be set so a 12 GB card proves one shard in about 20 seconds. That number is the first gate on the roadmap and is not measured yet. The first proofs exist: on 4 October 2026 an RTX 5090 proved a small two-transaction block in 1.4 seconds (2.7 seconds compressed), verified in 0.22 and 0.038 seconds, and a laptop CPU proved a three-shard block end to end in 19 minutes. Later that day the same card proved a full shard at the provisional size, 6.75 million prover gas, which executed in 60.8 million cycles: core proof 8.3 seconds, compressed proof 10.9 seconds, verified in 0.040 seconds; a four-shard block took 44.5 seconds of GPU stages end to end. Since 5 October 2026 shards are assigned and proven on the live devnet. The gate asks for a mid-range card, and an RTX 5090 is not one, so the gate stands open. Once the gate is measured, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface, so Igneum can adopt a better proof system when one exists by a miner-signalled release, and runs for ever on the current one if none is adopted.</p>
|
||||
<p>Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Target: shard size will be set so a 12 GB card proves one shard in about 20 seconds. That number is the phase 2 gate on the roadmap and is not measured yet on the card the gate names. The first proofs exist: on 4 October 2026 an RTX 5090 proved a small two-transaction block in 1.4 seconds (2.7 seconds compressed), verified in 0.22 and 0.038 seconds, and a laptop CPU proved a three-shard block end to end in 19 minutes. Later that day the same card proved a full shard at the provisional size, 6.75 million prover gas, which executed in 60.8 million cycles: core proof 8.3 seconds, compressed proof 10.9 seconds, verified in 0.040 seconds; a four-shard block took 44.5 seconds of GPU stages end to end. Since 5 October 2026 shards are assigned and proven on the live devnet. The gate asks for a mid-range card, and an RTX 5090 is not one, so the gate stands open. Once the gate is measured, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface, so Igneum can adopt a better proof system when one exists by a miner-signalled release, and runs for ever on the current one if none is adopted.</p>
|
||||
<h3>Proving for everyone else</h3>
|
||||
<p>The same miners accept proving jobs from other chains. Rollups post a job, a miner wins it, proves it, and is paid. The job market is permissionless. Jobs taken through Igneum's own market are paid in IGN and 10% of each fee is burned. The Igneum miner client also bids on other proving networks, where jobs are paid in those networks' currencies, and takes the best price. The proving market is small today. Igneum does not depend on it. No other proof-of-work chain has a seat in it.</p>
|
||||
<p>The same miners accept proving jobs from other chains. Rollups post a job, a miner wins it, proves it, and is paid. The job market is permissionless and is Designed, not yet built. At launch a job is paid on the customer's own chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum. Settlement in IGN, with 10% of each fee burned, follows when the proof bridge lets Igneum see the payment, in phase two. The Igneum miner client can also bid on other proving networks and take the best price, where a miner chooses to hold their collateral: Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation). The proving market is small today. Igneum does not depend on it. We know of no other proof-of-work chain selling proofs to other chains.</p>
|
||||
</section>
|
||||
|
||||
<section id="finality">
|
||||
<h2>Speed and finality, powered by miners alone</h2>
|
||||
<h3>Speed</h3>
|
||||
<p>Igneum orders blocks with GHOSTDAG, the BlockDAG consensus proven on Kaspa. Blocks arrive in parallel and are ordered rather than orphaned, so the chain runs at one block a second at launch with scheduled steps to four and ten. A transaction is included in about one second, against twelve on Ethereum, and locked in about two minutes against roughly thirteen. Emission per block is a schedule keyed to difficulty-adjusted time, and every block in the window is paid at that rate, red or blue, so coins track blocks within the accuracy of the difficulty controller.</p>
|
||||
<p>Igneum orders blocks with GHOSTDAG, the BlockDAG consensus Kaspa has run in production since 2021 (approximate), forked from rusty-kaspa. Blocks arrive in parallel and are ordered rather than orphaned, so the chain runs at one block a second at launch with scheduled steps to four and ten, the step plan Kaspa used for its own block-rate rise (approximate). A transaction is included in the DAG in about one second (an Ethereum slot is twelve) and locked by miners in about two minutes (Ethereum reaches finality in about thirteen, approximate). Inclusion is not confirmation on either chain, and the two finality mechanisms differ: Igneum's lock is a vote of miners weighted by 30 days of blocks, Ethereum's is economic, backed by slashed stake. Emission per block is a schedule keyed to difficulty-adjusted time, and every block in the window is paid at that rate, red or blue, so coins track blocks within the accuracy of the difficulty controller.</p>
|
||||
<h3>Finality</h3>
|
||||
<p>Every 30 seconds of chain a checkpoint forms, deep enough past the tip that the DAG will not reorder it. Every miner with at least 100 blocks in the last 30 days signs it, and the checkpoint locks when signatures representing two thirds of all the mining weight of those 30 days arrive. Once a checkpoint is locked it overrides the heaviest chain, so no amount of fresh hashrate can reorganise past it. In the chain's first month the weights behind those locks are thin, because nobody has a long history yet, and the chain leans on proof of work and its 12-hour finality depth the way every new proof-of-work chain does. On the devnet the first lock came two hours after genesis, at 77.4% of all weight from 17 vote keys (4 October 2026).</p>
|
||||
<p>Every 30 seconds of chain a checkpoint forms, deep enough past the tip that the DAG will not reorder it. Every miner with at least 100 blocks in the last 30 days signs it, and the checkpoint locks when signatures representing two thirds of all the mining weight of those 30 days arrive. Once a checkpoint is locked it overrides the heaviest chain, so fresh hashrate cannot reorganise past it. Two thirds of 30-day weight can. In the chain's first 30 days no checkpoint locks at all: the rule waits until the window holds 30 days of history (Implemented, the first-month gate, measured on test networks on 4 and 5 October 2026), so the chain runs on proof of work and its 12-hour finality depth the way every new proof-of-work chain does. On the devnet, whose window is two hours, the first lock came two hours after genesis, at 77.4% of all weight from 17 vote keys (4 October 2026).</p>
|
||||
<div class="pull">The word sustained is the whole defence. Block rewards go to whoever mines, new or old. The right to lock history is earned.</div>
|
||||
<p>A miner's vote weight is simply the blocks it has mined over the trailing 30 days, measured by work, so splitting into many keys buys nothing and joining a pool costs nothing. Hashrate that arrived today holds almost none of it. Even an attacker who brought the whole network's hashrate would need ten days of mining in public to hold a third of the weight, and twenty days to hold two thirds. At 51% of the network they never reach two thirds at all while the honest miners keep mining. Rental is priced by the hour. The only route left is to drive honest miners off the chain and hold two thirds for a month on the public hashrate charts, which is the same limit Bitcoin lives with, with a month's warning attached.</p>
|
||||
<p>A miner's vote weight is simply the blocks it has mined over the trailing 30 days, measured by work, so splitting into many keys buys nothing and joining a pool costs nothing. Hashrate that arrived today holds almost none of it. Even an attacker producing every block on the chain, with honest miners gone, would need ten days of mining in public to hold a third of the weight, and twenty to hold two thirds. An attacker matching the honest network needs twenty days for a third and never reaches two thirds while the honest miners keep mining. Rental is priced by the hour. The only route left is to drive honest miners off the chain and hold two thirds for a month on the public hashrate charts, which is the same limit Bitcoin lives with, with a month's warning attached. Pools carry their hashers' votes, so vote concentration equals pool concentration, and it is public.</p>
|
||||
<p>Two further rules close the gaps. A lock needs two thirds of all 30-day weight, so finality pauses whenever less than two thirds of that weight is connected and signing, until it returns or ages out of the window, up to 30 days, and the chain runs on proof of work meanwhile. The node reports the pause. A key that stops signing is reported as absent within two hours, which is how operators see a pause coming. Beneath the latest lock the depth to rely on is the finality depth: a node never switches to a chain forked more than 12 hours of median time back, and a certified checkpoint shortens that to its own age. Kaspa's one-hour merge depth is a limit on which old blocks a new block may merge, not a reorganisation bound. Signing two different checkpoints at the same height is equivocation, provable by anyone, and it strips the key of its vote for 30 days.</p>
|
||||
<h3>What is not here</h3>
|
||||
<p>No stake. No coin-holder class votes on anything. No anchoring into Bitcoin or any other chain. Nothing in Igneum's consensus depends on anything outside Igneum.</p>
|
||||
|
|
@ -466,9 +469,9 @@ body.all .pager{display:none}
|
|||
<section id="building">
|
||||
<h2>Building on Igneum</h2>
|
||||
<p>Anything that runs on Ethereum runs on Igneum unchanged. Same Solidity, same bytecode, same wallets, same tools, a different chain id. Builders get Ethereum semantics with one-second inclusion, finality in about two minutes, and gas priced for a chain that is not congested.</p>
|
||||
<p>Three things run on Igneum that run nowhere else.</p>
|
||||
<p>Three things Igneum offers at the base layer that we know no other EVM chain offers.</p>
|
||||
<ol>
|
||||
<li><strong>Proving as a native primitive.</strong> A contract can request a proof of any computation and pay for it in gas, and the miners produce it. A game proves a fair shuffle. A lending market proves its solvency. A rollup elsewhere posts a job and gets its proof back. No other EVM chain has a prover network in its base layer.</li>
|
||||
<li><strong>Proving as a native primitive.</strong> A contract can request a proof of any computation and pay for it in gas, and the miners produce it. A game proves a fair shuffle. A lending market proves its solvency. A rollup elsewhere posts a job and gets its proof back. We know of no other EVM chain with a prover network in its base layer.</li>
|
||||
<li><strong>Light clients.</strong> Because every block is proven, a phone or a browser verifies Igneum's state from one proof and a locked checkpoint it is given. Making the checkpoint itself self-verifying, which is what removes the multisig from bridges, needs a consensus proof and is phase two.</li>
|
||||
<li><strong>Rollups that settle here.</strong> A rollup posting to Igneum gets its proofs from the same miners that secure it, in the same flow. Settlement and proving in one place costs less than paying a proving network and a settlement layer separately.</li>
|
||||
</ol>
|
||||
|
|
@ -486,7 +489,7 @@ body.all .pager{display:none}
|
|||
|
||||
<section id="economics">
|
||||
<h2>Economics</h2>
|
||||
<p>The coin is IGN. It is gas, it is the proving currency, and it is what every outside customer pays in. Part of every payment is burned.</p>
|
||||
<p>The coin is IGN. It is gas and the proving currency, and part of every payment on Igneum is burned. Outside customers pay in their own currency on their own chain at launch; settlement in IGN with a 10% burn follows when the proof bridge lets Igneum see the payment, in phase two.</p>
|
||||
<h3>Supply</h3>
|
||||
<p>Fair launch. No premine, no pre-sale, no allocation to anyone. Hard cap of 4 billion IGN, approached and never reached, because emission starts at 1 billion a year and halves every two years for ever. Nearly a quarter of all supply is mined in the first year and half in the first two, so the people who show up early get the most. Emission ramps from 10% to 100% over the first 30 days so that nobody takes the first month before the rest of the world hears about it.</p>
|
||||
<div class="figure">
|
||||
|
|
@ -524,7 +527,7 @@ body.all .pager{display:none}
|
|||
</tbody>
|
||||
</table></div>
|
||||
<h3>Where fees go</h3>
|
||||
<p>The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits two ways: 80% to the miner and provers of that block, 20% to the apps whose code ran, by gas consumed inside each. External proving fees pay 90% to the provers who delivered and burn 10%. The hard cap fixes supply. Emission is untouched by any of this: every coin minted still goes to miners and provers.</p>
|
||||
<p>The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits two ways: 80% to the miner and provers of that block, 20% to the apps whose code ran, by gas consumed inside each. External proving fees, once they settle on Igneum, pay 90% to the provers who delivered and burn 10%. The hard cap fixes supply. Emission is untouched by any of this: every coin minted still goes to miners and provers.</p>
|
||||
<h3>Security after the subsidy</h3>
|
||||
<p>The cap stays at 4 billion. There is no tail emission. Long term, security is paid for by the proving market and by fees. Outside customers buy proofs as dollars-priced work settled in IGN, and 90% of every job goes to the provers who delivered it, so a prover's income does not depend on emission. The table shows the first year in which the block subsidy on its own pays miners less than the power of about 3,000 consumer cards, at three flat prices. The prices are inputs chosen to span two orders of magnitude. The model runs a 300 W card at 124 MH/s on electricity at USD 0.12 per kWh. One rule sits beside the cap. If external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the question of a tail reward goes to the miners' signalling vote. The protocol never changes emission by itself.</p>
|
||||
<div class="tbl"><table>
|
||||
|
|
@ -536,7 +539,7 @@ body.all .pager{display:none}
|
|||
</tbody>
|
||||
</table></div>
|
||||
<h3>No fund, no foundation, no fee to the team</h3>
|
||||
<p>There is no development fund. A switch that routes money to an address somebody controls is the first thing a critic points at, so Igneum has none. The protocol carries no fee to any team, foundation or fund. The team earns in the open: it runs provers in the job market and collects the app share on the contracts it deploys, like anyone else. If the community ever wants a grant mechanism, miners can add one by signalling.</p>
|
||||
<p>There is no development fund. A switch that routes money to an address somebody controls is the first thing a critic points at, so Igneum has none. The protocol carries no fee to any team, foundation or fund. The project earns in the open, and this is the full list: the optional 1% dev fee in the Ember miner software, off with one flag and audited on the chain; the provers it runs in the job market; any pool it operates; and the app share on the contracts it deploys, like anyone else. None of it is in the protocol, and the first item is the one a critic should quote: for as long as miners run Ember with the fee on, 1 block in 100 pays the project. If the community ever wants a grant mechanism, miners can add one by signalling.</p>
|
||||
</section>
|
||||
|
||||
<section id="miners">
|
||||
|
|
@ -551,16 +554,16 @@ body.all .pager{display:none}
|
|||
<tr><td>External proving jobs</td><td>Rollups and apps on other chains, priced in their money</td><td>No, but the market is small today and is upside, not a promise</td></tr>
|
||||
</tbody>
|
||||
</table></div>
|
||||
<p>The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners have the lowest marginal cost in the proving market and are the last provers to switch off.</p>
|
||||
<p>The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' marginal cost in the proving market is close to power, which is an edge over data-centre provers and nothing more.</p>
|
||||
<h3>Hardware</h3>
|
||||
<p>The dataset starts at 2 GB and grows by half a gigabyte a year, so a 4 GB card mines for about four years and an 8 GB card for more than a decade, approximate. 12 GB or more proves full shards. NVIDIA and AMD both work, because the mining program is generated for the architecture both share and the proof system is hash-based. Apple's chips are GPUs with unified memory, so Macs mine too. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.</p>
|
||||
<p>The dataset starts at 2 GB and grows by half a gigabyte a year, so a 4 GB card mines for about four years and an 8 GB card for more than a decade, approximate. 12 GB or more proves full shards. NVIDIA and AMD both work, because the mining program is generated for the architecture both share and the proof system is hash-based. Apple's chips are GPUs with unified memory, so Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second, an Apple M5 Max beside an RTX 5090 on the live devnet, 4 October 2026. A Mac is a poor miner per dollar. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.</p>
|
||||
<h3>What a miner's hour looks like</h3>
|
||||
<p>The card hashes the lottery continuously. When the client sees a shard or an external job it can win, it switches the card to proving for a few seconds, posts the proof, and goes back to hashing. The client does the switching and the miner sees one balance.</p>
|
||||
<p>The protocol carries no fee: no dev fund, no cut to any team. Ember, the miner software, takes an optional 1% dev fee, the way other GPU miners do. One block template in 100 is requested with the dev address instead of yours, by a counter, not a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. One flag turns it off (<code>--dev-fee 0</code>, a switch in the app, a line in the HiveOS config). The miner prints the fee and the address when it starts. Any other client is welcome.</p>
|
||||
<h3>One click, for everyone else</h3>
|
||||
<p>Farm operators get a HiveOS package. Everyone else gets Igneum Ember: install it on Windows, macOS or Linux, press one button, and the card is mining and proving to a key the app made for you, with earnings shown in IGN and in your currency, and mining paused while you game. It is the same client with a face on it. The app shows you the key and has you save it before mining starts, offers a hardware wallet for your earnings, updates itself from releases signed by the project's release key with a switch to turn that off, and is downloaded only from this domain or the repository with its hash shown beside the button. The next section says what is shipped and what is still a design. Nobody from Igneum will ever ask for your seed. Mining never runs in a browser, because browser compute is slow and browser mining has meant malware since Coinhive. The browser is for the dashboard, and for verifying the chain.</p>
|
||||
<h3>Fair launch, announced</h3>
|
||||
<p>Launch date and miner software published a month ahead. Pools live on testnet. HiveOS support on day one. The founders mine from genesis like everyone else, with disclosed addresses and the same software. Nobody has coins before block one.</p>
|
||||
<p>Launch date and miner software published a month ahead. Pools live on testnet. HiveOS support on day one. The founders mine from genesis like everyone else, with disclosed addresses and the same software. Nobody has coins before block one. The first 30 days of mainnet run on proof of work alone, with no locked checkpoint, while vote weights build; anyone crediting deposits in that month should treat Igneum as plain proof of work with a 12-hour depth.</p>
|
||||
</section>
|
||||
|
||||
<section id="ember">
|
||||
|
|
@ -631,19 +634,19 @@ body.all .pager{display:none}
|
|||
|
||||
<section id="governance">
|
||||
<h2>Governance</h2>
|
||||
<p>Igneum is governed by the people who power it, and by nobody else.</p>
|
||||
<p>Igneum is governed by the hashrate that powers it. Pools carry their hashers' votes, so pool concentration is the governance risk, and it is public: on the devnet the top three vote keys held 34.5% of 8,090 blocks on 4 October 2026, measured.</p>
|
||||
<ul>
|
||||
<li><strong>Nothing needs a scheduled upgrade.</strong> The mining program, the dataset and the finality rules run themselves for ever. If the community ever ships an improvement, a better proof system or a block-rate step, it is published with test vectors at least three months ahead and activates only when 90% of blocks signal readiness. Developers can write code. Only miners can turn it on.</li>
|
||||
<li><strong>Miners set what genesis leaves open.</strong> A parameter that the genesis rules leave to miners is set by signalling: a proposal passes or fails on 60% of hashrate over two weeks. There is no fund to vote on and no fee to any team, foundation or fund.</li>
|
||||
<li><strong>Pools cannot censor.</strong> Igneum uses Stratum v2 from day one, so each miner chooses its own transactions even inside a pool.</li>
|
||||
<li><strong>There are no admin keys.</strong> Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy.</li>
|
||||
<li><strong>Pools can be bypassed on transaction choice.</strong> Igneum ships Stratum v2 job declaration from day one, so a miner chooses its own transactions when its pool supports it. Pools can decline, and vote keys stay with the pool. Designed: the pool protocol is specification section 9, not yet run by any pool.</li>
|
||||
<li><strong>There are no admin keys in consensus.</strong> Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy. The genesis apps are contracts, and each publishes its own upgrade and key policy before launch; the bridge's is the one to read. Designed, open item O-5.4.</li>
|
||||
<li><strong>The chain runs without its founders.</strong> Blocks, proofs and finality need no one. A second independent node client is the first priority after launch, and anyone can build it.</li>
|
||||
</ul>
|
||||
</section>
|
||||
|
||||
<section id="roadmap">
|
||||
<h2>Roadmap</h2>
|
||||
<p>Thirteen months from specification to a fair launch, with four public gates. Each gate is a measurement published whether it passes or fails. Miss it and the phase repeats or the project stops.</p>
|
||||
<p>Thirteen months from specification to a fair launch, with four public gates. Each gate is a measurement published whether it passes or fails. Miss it and the phase repeats or the project stops. Each piece of Igneum has a precedent in production somewhere; no chain combines them, and the combination is the risk the gates price.</p>
|
||||
<div class="tbl"><table>
|
||||
<thead><tr><th>Phase</th><th>When</th><th>What</th><th>Gate to pass</th></tr></thead>
|
||||
<tbody>
|
||||
|
|
@ -652,10 +655,10 @@ body.all .pager{display:none}
|
|||
<tr><td>3. Devnet</td><td class="num">Started 3 Oct 2026, 20 nodes by Mar 2027</td><td>BlockDAG node with the new mining program and EVM execution, 20 nodes. Live now: 1 block a second, difficulty v2, finality v2 locks, proving v0, Ember on every machine. Not yet measured on the live chain: the proof lag behind the tip</td><td>1 block a second held with proofs under 60 s behind the tip</td></tr>
|
||||
<tr><td>4. Finality and job market</td><td class="num">Apr to Jul 2027</td><td>Sustained-mining finality, external proving jobs, miner client with auto-switching</td><td>Finality design passes external review and one rollup signs for testnet</td></tr>
|
||||
<tr><td>5. Public testnet</td><td class="num">Aug to Oct 2027</td><td>One-click miner app on Windows, macOS and Linux, HiveOS, pools, the first rollup as a proving customer, no coin yet</td><td>1,000 independent miners run 30 days and rollup proofs are delivered on time</td></tr>
|
||||
<tr><td>6. Mainnet fair launch</td><td class="num">Nov 2027</td><td>Genesis with no premine, 30-day ramp, exchange listings after</td><td></td></tr>
|
||||
<tr><td>6. Mainnet fair launch</td><td class="num">Nov 2027</td><td>Genesis with no premine, 30-day ramp. No listing is arranged, promised or sought by the project</td><td></td></tr>
|
||||
</tbody>
|
||||
</table></div>
|
||||
<p>Phase two decides everything. If consumer GPUs cannot prove shards fast enough, Igneum says so and does not launch on promises.</p>
|
||||
<p>Dates slip. Gates do not. Phase two decides everything. If consumer GPUs cannot prove shards fast enough, Igneum says so and does not launch on promises.</p>
|
||||
<h3>What ships next: Ember 0.3.6</h3>
|
||||
<p>The proving activation of 5 October 2026 set the next release. Each item is in the 0.3.6 plan; none is on the fleet yet.</p>
|
||||
<div class="tbl"><table>
|
||||
|
|
@ -677,13 +680,14 @@ body.all .pager{display:none}
|
|||
<h3>Kaspa was GPU-mined too, and IceRiver shipped a chip within two years.</h3>
|
||||
<p>Kaspa never promised chip resistance, and its hash was one fixed function, simple enough to put on silicon. Igneum's program is different every hour, its dataset grows past any fixed memory, and its program space widens every era, with no human involved. In January 2027 the benchmark tool is public, so you run it on your own card and post the number to a leaderboard by card model. A standing bounty pays anyone who can show a chip design that beats a GPU by more than 2x. And if a chip ever appears, miners are the ones who signal the response.</p>
|
||||
<h3>Finality weighted by mining history is new. New gets attacked.</h3>
|
||||
<p>Correct, and it is the first thing the external review is paid to break. The specification is public, the review is gate 3 with named reviewers and a bounty, and the chain runs on plain GHOSTDAG without it, so the rule can be fixed without stopping the chain.</p>
|
||||
<p>Correct, and it is the first thing the external review will be paid to break. The specification is public; reviewers will be named and paid before gate 3, and a bounty is attached. Until then every finality claim here is a design claim backed by simulations and by the devnet, and the chain runs on plain GHOSTDAG without the rule, so it can be fixed without stopping the chain.</p>
|
||||
<h3>Who are you?</h3>
|
||||
<p>The founders mine from genesis with disclosed addresses and the same software as everyone else, and hold no coins before block one. The team page is published at public testnet, with the people, the mining addresses and the code history.</p>
|
||||
<p>One founder, pseudonymous until the team page at public testnet, working with AI systems. The design, the hostile reviews, the code, the simulators and this document were produced that way, and the commit history says so. What that does and does not mean: the measurements are measurements, reproducible from the commands in the engineering log; the simulators are code anyone can run; the design claims stay design claims until people with names have tried to break them. Every criticism the project expects is kept in a ledger with its honest answer, and the entries that were right are marked conceded; the ledger is published with the node repository. No cryptographer is hired yet; the plan budgets one for phases 1 and 2, and external reviewers are named and paid before gate 3.</p>
|
||||
<p>The founders mine from genesis with disclosed addresses and the same software as everyone else, and hold no coins before block one. The team page is published at public testnet, with the mining addresses and the code history.</p>
|
||||
<h3>Where is the miner?</h3>
|
||||
<p>On the devnet now. Igneum Ember runs on Windows, macOS and Linux, a HiveOS package exists, and the devnet's coins have no value. The public benchmark with a leaderboard by card model is January 2027. Pools and the public testnet are August 2027. All of it before any coin exists. Nothing is asked of a miner before they can run something. The <a href="#ember">Ember section</a> says what is shipped and what is still owed.</p>
|
||||
<h3>Will my card still pay in a bear market?</h3>
|
||||
<p>Block reward and in-chain proving move with the price. Proving for other chains is priced in the customer's money, and it is a small market today. What Igneum can promise is that its miners have the lowest cost in that market, because the card is already running on domestic power, so they are the last to switch off. That is an edge and nothing more.</p>
|
||||
<p>Block reward and in-chain proving move with the price. Proving for other chains is priced in the customer's money, and it is a small market today. What Igneum can promise is that its miners' marginal cost in that market is close to power, because the card is already running on domestic power. That is an edge over data-centre provers and nothing more.</p>
|
||||
</section>
|
||||
|
||||
<section id="builders-ask">
|
||||
|
|
@ -704,9 +708,9 @@ body.all .pager{display:none}
|
|||
<h2>Built on the shoulders</h2>
|
||||
<p>Every borrowed part of Igneum is credited here, in public. The rule, decided on 3 October 2026: credit every component, replace only what the design requires, and measure every change. Nothing was taken quietly.</p>
|
||||
<ul>
|
||||
<li><strong>Kaspa, rusty-kaspa (ISC).</strong> The GHOSTDAG ordering and the node Igneum is forked from, at v2.1.0; the sampled difficulty rule is kept as the retarget.</li>
|
||||
<li><strong>Kaspa, rusty-kaspa (ISC).</strong> The GHOSTDAG ordering and the node Igneum is forked from, at v2.1.0; the sampled difficulty rule is kept as the retarget; the block-rate step plan follows Kaspa's own rise (approximate).</li>
|
||||
<li><strong>Monero, RandomX by tevador (BSD).</strong> The random-program idea and the small-cache, large-dataset design, rebuilt for GPUs with a program per hour instead of a program per hash.</li>
|
||||
<li><strong>ProgPoW and Ravencoin's KAWPOW.</strong> The first GPU randomisation precedents; they randomised the maths inside a fixed shape, Igneum regenerates the whole program.</li>
|
||||
<li><strong>ProgPoW and Ravencoin's KAWPOW.</strong> The first GPU randomisation precedents; they randomised the maths inside a fixed shape, Igneum regenerates the whole program. Cited from memory until their repositories are cloned beside the others, approximate.</li>
|
||||
<li><strong>LWMA by Zawy and Monero's trimmed window.</strong> Difficulty precedents studied for the hourly hash-speed step; no code taken.</li>
|
||||
<li><strong>Chia, chiavdf (Apache 2.0) and Wesolowski's proof.</strong> The class-group delay between a locked checkpoint and the next program seed, ported into the prototype.</li>
|
||||
<li><strong>Ethereum.</strong> The virtual machine itself, run through revm (MIT), with its semantics restated for a DAG.</li>
|
||||
|
|
@ -715,7 +719,7 @@ body.all .pager{display:none}
|
|||
<li><strong>Bitcoin's bech32 and Bitcoin Cash's CashAddr checksum.</strong> The address format, through Kaspa, with Igneum prefixes.</li>
|
||||
<li><strong>BLAKE2b, BLAKE3, SHA-256, Keccak.</strong> The hashes the node already uses, unchanged. ChaCha, SplitMix64 and FNV-1a inside the lottery hash, implemented from their definitions.</li>
|
||||
</ul>
|
||||
<p>What is Igneum's own: the hourly header-bound GPU program, the sustained-mining finality rule, two-dimensional gas with the per-frame app share, the shard market and proving precompile, and the automatic era draws. The full table, with what changed in each component, why the design needed it, and the measurement or specification section that covers it, is <code>docs/provenance.md</code> in the repository and is published with it in January 2027. Licences stated from memory are marked approximate there and verified before the repository opens.</p>
|
||||
<p>What is Igneum's own: the hourly header-bound GPU program, the sustained-mining finality rule, two-dimensional gas with the per-frame app share, the shard market and proving precompile, and the automatic era draws. The full table, with what changed in each component, why the design needed it, and the measurement or specification section that covers it, is <code>docs/provenance.md</code> in the repository and is published with it at the public testnet. Licences stated from memory are marked approximate there and verified before the repository opens.</p>
|
||||
</section>
|
||||
|
||||
<section id="limits">
|
||||
|
|
@ -723,13 +727,16 @@ body.all .pager{display:none}
|
|||
<p>Here are the limits, stated before anyone else states them.</p>
|
||||
<ul>
|
||||
<li><strong>A proof in seconds.</strong> Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.</li>
|
||||
<li><strong>A chip is impossible.</strong> No. A chip is pointless, because the target moves before it ships. The honest efficiency ceiling for a fixed chip on a memory-bound program is under 2x, approximate, and Igneum's generator changes under it every hour.</li>
|
||||
<li><strong>A guaranteed income floor.</strong> No. External proving is a small market today. Igneum's miners have the lowest cost in it, which is an edge and nothing more.</li>
|
||||
<li><strong>Finality that no amount of hardware can break.</strong> No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded by the 12-hour finality depth. Reaching a third takes at least ten days of the whole network's hashrate, in public. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose. The floor is also bounded in time: an honest partition that lasts long enough for each side's own new blocks to reach two thirds of its window locks on both sides, about ten days of a 30-day window at an even split, and an operator must then resolve it (measured on a test network, 4 October 2026).</li>
|
||||
<li><strong>A chip is impossible.</strong> No. A chip is a bad bet, because the target moves before it ships. The efficiency ceiling for a fixed chip on a memory-bound program is a target of under 2x, not a measurement, and Igneum's generator changes under it every hour. Monero's seven years without a public chip are precedent, not proof.</li>
|
||||
<li><strong>A guaranteed income floor.</strong> No. External proving is a small market today. Igneum's miners' marginal cost in it is close to power, which is an edge and nothing more.</li>
|
||||
<li><strong>A memory-hard prototype on every vendor.</strong> Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.</li>
|
||||
<li><strong>Finality in the first month.</strong> No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.</li>
|
||||
<li><strong>A cryptography team.</strong> Not yet. One founder working with AI systems wrote the design and the code; external reviewers are named and paid before gate 3, and every security claim here is a design claim until then.</li>
|
||||
<li><strong>Finality that no amount of hardware can break.</strong> No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded by the 12-hour finality depth. Reaching a third takes at least ten days of producing every block on the chain, in public; an attacker matching the honest network needs twenty days for a third and never reaches two thirds. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose. The floor is also bounded in time: an honest partition that lasts long enough for each side's own new blocks to reach two thirds of its window locks on both sides, about ten days of a 30-day window at an even split, and an operator must then resolve it (measured on a test network, 4 October 2026).</li>
|
||||
<li><strong>Finality that never pauses.</strong> No. A lock needs two thirds of all 30-day mining weight. Whenever less than two thirds of that weight is connected and signing, finality pauses until it returns or ages out of the window, up to 30 days. The chain keeps running on proof of work and the node reports the pause.</li>
|
||||
<li><strong>A finished protocol.</strong> The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.</li>
|
||||
</ul>
|
||||
<p>Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything.</p>
|
||||
<p>Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything. Found an error, or a criticism this document does not answer? Open an issue on the public specification repository: <a href="https://github.com/igneum-network/spec/issues" rel="noopener">github.com/igneum-network/spec/issues</a>. A mailbox follows; there is no other contact route yet.</p>
|
||||
</section>
|
||||
</article>
|
||||
</div>
|
||||
|
|
|
|||
Loading…
Reference in a new issue