docs/analysis/horizon/new-pow.md sections 0 to 9: scheme A (mining is proving) never, on bytes,
the verifier and sampleability; scheme B (the tensor-shaped integer shadow) prototyped as
proto-newpow/mma-shadow and measured, never as class content on the energy reading, with the R8
two-output correction; scheme C (proof of stored state, sd1: the daily dataset derived from the
execution state) prototyped as proto-newpow/state-dataset, measured on the GPU and the box's
CPU, and put forward as the class v5 candidate with its spec items and the Devnet 2 gate. The
lane's standing rule: a shadow lever only works through joules the honest card is forced to
spend, so shadow work goes where the GPU is least efficient per op. Chip rows in
sim/horizon/new-pow/chip_rows.py by the chip-model-v3 method. Rented box addresses replaced by
placeholders in the READMEs and the run script.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Utility curves for IGN beyond gas with dollar inputs labelled; the proving price as the
forgone subsidy (1 / network hash) against Boundless's published rate; the adopted job floor
overprices the market above about USD 0.014 per IGN; a ten-year security budget with the
measured 5090 row (sustained hash USD 24.8 per GH/s-day against USD 281 rented, so the 20-day
34 percent weight attack costs 11.8x the honest fleet at every price); sim/economy re-run with
the eleven measured cards under eight stresses (T1 to T5 hold; a ten-day prover refusal strands
547,570 IGN a day of pool credit in the escrow with no rule to return it); the dev fee, the
signalling game, and the twelve-row table of what Kaspa, Monero, Ethereum and the zk rollups
did (rusty-kaspa cited by file and line).
Models: sim/horizon/economy-and-utility/ (utility.py, stress.py, security_budget_10y.py,
signal_game.py, devfee.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/analysis/51-percent.md: what a 51 percent attacker can and cannot do on Igneum, with
numbers (the selected-chain race over a 90-s hold, the lock as the reorder bound, the veto
at 1/3 of weight and its rental cost, the departure case and the LEAVE item, the p2p surface).
docs/analysis/horizon/consensus-security.md: the attack catalogue across GHOSTDAG ordering,
the difficulty rule, the finality weight, miner signalling, proof records, the exec layer and
p2p, each with the bound and the rental cost at the measured USD 11.7 per GH/s-hour; the
pruned-node unwrap class with its sibling list in the sync and IBD flows; fourteen ranked
defences, three of them not recommended with the reason.
Models and results: sim/horizon/consensus-security/ (ghostdag_sim.py, finality_horizon.py,
cost_model.py, signalling.py, result files).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The 6 October 2026 pause from the observer rows: 20 keys holding 42.7 percent of the frozen
voter table left in three minutes; locks formed without the hub; the 2/3 rule paused at
checkpoint 6843 (53.1 percent of total) and the frozen table (Q5) held the pause for a window
where rule v2 would have locked after 35 minutes. Candidate rules run in a copy of the finality
simulator (seeds 7, 11, 13): only the departure announcement keeps 0 conflicting locks and ends
the pause under an hour. Weight capture priced at the measured USD 11.7 per GH/s-hour: the veto
0.52 x N for 30 days (USD 4,300 per GH/s of network), a lock alone 2.03 x N. Lock delay by voter
count measured on node 1; the ZK light client and prover attestations costed.
Models: sim/horizon/finality-and-weight/ (finality_horizon.py, weight_capture.py,
lightclient_cost.py, merge_results.py, results/).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead's 6 October 2026 ask: deep backward and forward research across the hash, finality,
economy, network and every shipped surface. This commit carries the first three lanes.
- docs/analysis/horizon/algorithm.md: the chip model on the 6 October numbers (f = 1 GDDR7
chip 5.7x per joule against the 5090 at class v3, 2.1x at class v4 with k = 1), the FPGA
lane tightened to 0.30x to 0.47x per watt, the reserve R0 to R8, the reconciled shadow-N
ladder (section 5.3a) with HBM4 and three verifier brackets, the first measured verifier
proxy on igneum-build-1 (class v4 5.06 ms cold, dr736 10.51: out), the dataset schedule
to 2030; model sim/horizon/algorithm/model.py.
- docs/analysis/horizon/frontier.md: sixteen ideas ranked by payoff over difficulty with the
Monero and Kaspa attacks, prior art cited, the honest never column; model
sim/horizon/frontier/frontier_model.py.
- docs/analysis/horizon/new-pow.md sections 0 to 4: three new proof-of-work schemes defined,
reviewed in two personas, scheme A (mining is proving) ruled out on bytes and
sampleability, B and C in prototype on two rented 4090s; measured rows follow.
- docs/analysis/horizon-2026-10.md: the summary skeleton and the lane table.
Every rental cost cites docs/bench-log.md "Rental cost of hash, 6 October 2026".
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
PC 2 job run-ca3-shadow-pc2-20261006 (card empty, every pack bit-exact against the Mac): the 5090 holds its rate to
150,800 ops per hash and loses 2.7 percent at 199,600 under the app's 431 W cap, which binds from 102,100 ops up and
takes the clock from 3,037 to 1,834 MHz (86 MH/s at 330,700 ops); 350 W at the control, 2.65 to 3.27 microjoules per
hash; marginal ALU energy 10 to 13 pJ per counted op. Clock rows OWED (nvidia-smi refused -lgc without rights). Chip
side at N = 100,000 and k = 1: 2.1x over the 5090 on GDDR7, 0.9x over the M5 Max. GO at mx8+sh256x27.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The M5 Max ladder (Metal, packbench, IOReport GPU and DRAM watts without root): latency-bound to about 100,000 ops per
hash, the 5 percent point about 130,000, 11 to 27 W GPU at 100,000 ops, 0.78 to 1.40 microjoules per hash; the
verifier's law 2.06 ms + 3.2 us per 1,000 shadow instructions per warp on one core; every pack bit-exact. The
analysis file with the knob, the chip side (k = 1, 1.5, 0.3), the gates and the consequences; the bench-log entry;
the 5090 rows pending the PC 2 job (the playbook now carries the core-clock rows and the sh256x40 rung).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/plans/counter-asic-3-derivation.md (the design, the acceptance test, the interpreter, the allowance argument,
the measurements, the PROPOSED reserve entry R0 for 1.13.2, what is owed), docs/analysis/chip-model-v3.md section 6
(the per-day derivation rows at 1.0x to 3x allowances), the bench-log entry, relay/playbooks/ca3-derive-pc2.ps1
(one PC 2 job: self-fetched packs zip, the installed worker through NVRTC, the card off only under test with its
key from settings.json). Verifier 4.875 / 4.944 ms per unit on one M5 Max core under the measure lock against
x8's 2.061 / 2.063; Metal build 29 ms against 22; hash rate equal; bit-exact on Metal and Apple OpenCL.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
f = 0, 0.25, 0.5, 0.75, 1 on GDDR7 (the 5090's board), one HBM3 stack and eight HBM3 stacks, scored in energy per
hash, reads in flight per watt, rate per chip and dollars per MH/s against the RTX 5090 at 136.1 MH/s and 326 W.
The curve is monotone toward f = 1; the f = 1 chip reads 5.1x (GDDR7) to 9.2x (HBM3) per joule in the model and
2.1x to 4.8x by the Ethash precedent: over 2x. The mixer and item 2 do not touch it; the levers named are the
5090's watts under a power cap (a PC 2 job, owed) and program work in the latency shadow. Inputs cited with URLs
read 6 October 2026; the mixer counted from memhard.rs at 128 hoisted / 144 unhoisted ops per application.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
the project lead, 5 October 2026 22:05 UTC: if the GPU-server patch does not enable 12 GB cards, research proving and see if there are different methods. docs/analysis/proving-methods.md: (1) the memory anatomy of SP1 6.8.1 from its code (the 20 GB panic in sp1-gpu builder.rs, the maximum-sized trace buffers, the mempool that never releases, the fixed recursion shape), the theoretical floor for the adopted shard (about 10 to 11 GB, approximate); (2) the survey: SP1, RISC Zero, Airbender, ZisK, OpenVM, Pico, Ziren, Stwo, Jolt, Ceno, Nexus, Valida, Powdr, Binius, the 2026 entrants, the sumcheck and GKR family, folding, continuations, distributed proving, AMD and Apple backends, every claim cited; (3) per route the change to the guest, aggregator and node verifier, the cost in agent days, the risk, and whether 12 GB under 60 s is reached; (4) the ranking: re-size SP1's server with S_p as the dial and one server per card (no consensus change), RISC Zero as version 2 for the fallback and Apple, the sumcheck family in five years; (5) the tier consequences and the public line.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
igneum-prove-core carries the node's fees.rs (PgasTable, FeeParams PROTOTYPE and CALIBRATED_V1,
FeeSchedule::at); the shard input and every fixture carry the schedule and the block's DAA score; the executor
reads the set at that score, raises the base fees to its floors and meters with its intrinsic, B_p and modexp
entry, as the node's execute_segment does. The 328-byte statement is unchanged: the node's native veto pins the
schedule (a new layout would be a consensus change for every node). Exporter: schedule and daaScore from the
dump (gen.mjs writes them), per-segment switch on replay, S_p from the set. Fixtures from one simnet chain across
the switch at DAA 800: fees-switch-prototype (block 51), fees-v1-shards2 (351), fees-v1-shards3 (355); 358
segments replayed, every state root the node's. Host tests on both sides. Guest re-pinned: shard
0x2b1a81cb..., aggregator 0x474678f3...; pinned-guests-check passes.
Node fork 2b6d23ef unchanged (igneum-exec tests 11 passed). Digest for the override with
fees_v1_activation_daa 210000: ab8847da538dead1dc10e046dfaadab3c1c35928e3748810c4e050d4a886087a.
Runbook docs/plans/fee-switch-devnet.md; infra/devnet/restart-hand-nodes.sh and restart-seed.sh take the
override object (the hand nodes and the seed run 20139145 today and must move to 2b6d23ef first). One line on
the live page, spec 5.11, the testnet README, the floor analysis, the bench log and the journey.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Owner's decision, 5 October 2026: the proposed testnet identity (docs/testnet/README.md) and the proposed fee floors
and prover-gas table (docs/analysis/base-fee-floor.md, spec 05 section 5.10) are adopted as proposed. The three
documents now say "adopted 5 October 2026" with the sign-off noted and the per-network rule written in: the testnet
and the mainnet carry calibrated v1 from genesis; the devnet and the simnet keep the prototype set until the
fees_v1_activation_daa height switch (fork branch release-0.3.6) moves them.
Conflicts (generated site files): index.html keeps the 0.3.5 dev-fee sentence and testnet-prep's testnet-terms card;
litepaper.html keeps the 0.3.5 two-paragraph dev-fee text and testnet-prep's MetaMask paragraph; journey.json keeps
the 0.3.5 feed (newest 40); sitemap.xml keeps /miners and /wallet. Site rebuilt with node site/build.mjs.
Also: infra/fast-time/override-60x.json carries fees_v1_activation_daa 0 (the fork's fast-time test wants every
override field); docs/plans/release-0.3.6.md (the inputs push must run from this tree before the workflow verifies
the signature; the devnet rollout of the fee floor as a height switch; the morning order).
Checks: node site/build.mjs; link-check 324 links 0 broken; check-workflow-shell 0 findings; test-inputs-signing.sh
16 of 16 with the signer built from this tree; bash -n on the four shell files; the PowerShell parse rule at the
0.3.5 baseline (3 hits, unchanged).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- docs/analysis/base-fee-floor.md: the base-fee floors (100 gwei per gas, 10,000 gwei per pgas), B_p 120,000 and
S_p 30,000 pgas, the calibrated v1 pgas table (intrinsic 300, modexp 10 + 1 per 10 bytes) from the measured 44
cycles per EVM gas and 9 cycles per pgas, with the arithmetic and a stated price assumption; spec 05 section 5.10.
The parameters are implemented on the node fork branch testnet-params (vendor, not in this repository).
- docs/testnet/README.md: igneum-testnet-1 (chain id 4462, ports 268xx, frozen genesis 2026-10-05T00:00:00Z with
its message and hash, mainnet finality window, every switch from genesis, no override file) and the reset policy.
Every value proposed, for the morning sign-off.
- docs/plans/history-rewrite.md: G14, the exact git-filter-repo pass, the dry run on a throwaway mirror clone (0
identity hits, 0 secrets, every stamp +0000, 312 commits), what breaks and the order for the morning.
- G13: app/igneum-app/src/inputs.rs and igneum-ota-sign sign-inputs / verify-inputs; push-inputs.sh signs
payload-inputs.json with the OTA key and pins the node commit (packaging/windows/node-source.pin);
windows.yml verifies the signature with the embedded key, the zip, every file and the pin before building and
uploads the verified record; fetch-ci-artifacts.sh signs the update manifest only with --sign-manifest <run-id>
after re-verifying that run's inputs. test-inputs-signing.sh (16 cases) and tools/ci/check-workflow-shell.mjs.
- site: testnet terms on the download section, wallet.html (wallet_addEthereumChain, chain ids 4462/4463, IGN, 18
decimals), the litepaper's app paragraph (MetaMask and the coming Igneum Wallet, no hardware wallet) and the
miner fee sentence (no protocol fee; optional 1% in the miner software, off with one flag). node site/build.mjs
and the link check pass.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Live devnet v4: a second RTX 5090 joining 7 minutes into an epoch left the whole-epoch reference lane polluted for the hour; the short lane read 11 to 25% above it and the 25% trigger flipped between the two for 40 minutes (102M to 164M, 54 to 81 blocks a minute). Record and hash-rate truth under sim/difficulty/records/. sim.py gains a DAG model (miners on nodes with igneum-miner's template staleness, GHOSTDAG, the rule as the node runs it) and --live replay: std of log difficulty 0.115 against the record's 0.134, 4.3 peaks of 1.31x against 4 of 1.37x. The brief's candidates (short lane 240/360, ease clamp 3%, clamp once per DAA second, hysteresis, median of three) leave 0.09 to 0.13; capping the reference lane at the newest 600 blocks of the epoch gives 0.026 with no flips. Rule v2 = that cap, epoch lane only, behind difficulty_v2_activation_daa (devnet-v4 fork). Attack suite and synthetic set before and after, 3-node test network of the switch (testnet_v2.py), analysis document, spec 2.3, bench-log entry, ledger M24, fast-time file carries the new field.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Spec 2.3: rule 1 measures every chain step on a sanitised clock stored per header
(c(b) = max(c(p) + clamp(t(b) - c(p), -20 T, +20 T), t(b) - 60 T), step min(c(b) - c(p),
20 T)); rule 4 bounds the output to [2^128, MAX_DIFFICULTY_TARGET]; the timestamp rules
are Igneum's own, 10 s ahead of the clock and 10 s behind the selected parent beside the
unchanged past-median rule; new parameter rows, the bounds paragraph rewritten (the old
"next honest block cancels it" was the attack), the attack and test-network results added.
sim/difficulty/sim.py: class Igneum carries the same clock, lag bound and floor, so the
rule as simulated is the rule as coded (attacks.py's igneum-san is now identical to it).
docs/analysis/difficulty-2026-10-03.md section 11: the attack, the three parts, before and
after tables (simulator seeds 7 to 9, base-profile regression within 10% on the 3-seed
means, pool hopping unchanged, the two 15-minute 3-node forger runs), unit tests, limits.
docs/bench-log.md: the 4 October entry. docs/fud-ledger.md: M23, status Fixed.
Node side: vendor/igneum-node branch difficulty, commit 52eacad9.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
No per-job growth in any worker or in the miner's memory. The STATUS rates are cumulative averages
(a fast first interval decays by construction), and the miner's Seeder walks the selected chain from
the sink to the epoch start on every memo miss (one getBlock per block, up to 3,600), a gap between
jobs that grew 0.10 s to 0.33 s across epoch 2 on the PC and reset at the epoch boundary while the
difficulty held. Reproduced on the Metal worker (churn on, off, on). One versus eight workers at two
fixed difficulties: 4% and 1% constant cost, no decay. Fix as a unified diff, not applied.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
sim/economy/sim.py: 1,000 operators choosing MINE, PROVE, HYBRID or OFF per card class with their own clients; sortition by weight with the 10-s window then open claiming, external jobs with the 90/10 split, backlog rule, difficulty clamps, GBM price. Scenarios a to f, 5 seeds: no backlog, no window miss, hash floor 0.74 of pre-event. Traffic sensitivity finds the shortage oscillation only above the proving fleet's capacity (100 to 300 shards per block); at 100 the sortition window (10 s to 20 s) is the lever that removes it. docs/analysis/economy-2026-10-04.md holds the model, assumptions, results, worst case and the proposal (window = p90 shard time plus a swap, 25 s at today's targets; B_p tied to the live fleet), not applied.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs/evidence.md and site/evidence.html: 28 public claims with one of five status labels (7 designed, 3 implemented, 18 tested by the team, 0 reproduced externally, 0 reviewed independently), version or commit, the reproducible test, the result with date and machine, and independent verification (none yet for every row). Evidence link in the homepage nav and the generated pages' nav.
docs/benchmarks/proving-e2e.md: replaces the 20-second shard gate with three fixed workloads, job-received-to-accepted-proof latency, cost per proof, the eligible card list with mining and proving reported separately, the verbatim acceptance standard and the three-unrelated-operator protocol.
docs/plans/funding.md: cost, what is funded (founder's means, the client's 1% fee once there is mining), what waits on revenue, what pauses.
docs/analysis/security-budget.md: emission through six halvings at three price inputs, miners and provers separate from burns, the USD 1M floor and the year it is crossed.
docs/design/payment-routes.md: Mermaid flowchart and table of every flow, with operator, app, team and protocol revenue labelled.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>