igneum/docs/ledger-public.md

54 KiB

Igneum criticism ledger, public shape

Generated by tools/ledger/export-public.mjs from docs/fud-ledger.md; a gate check fails when the two drift. One row per item: the claim or criticism, its status, what was done, and the evidence. Internal identifiers, times of day and team-member names are left out on purpose; the full ledger is published with the repository.

191 items. By status: Conceded, stated 52; Fixed 30; Decided 22; Fixed on a branch, pending merge 14; Answered by design 9; Answered with evidence 6; Fixed, stated 4; Closed by rule 3; Open 3; Answered by design, with a correction to our own text 1; Answered with evidence, stated 1; Answered by design for finality, Conceded for the lottery 1; Conceded, implemented, stated 1; Rule implemented and measured; launch month simulated 1; Answered by design, with the concession stated 1; Conceded, stated in the litepaper and the design doc 1; Answered with evidence at 1 block/s 1; Conceded, stated in the simulation report 1; Answered by design, with the dependency conceded. Update 7… 1; Conceded, stated in the litepaper, with the dial explained 1; Closed by spec 1; Conceded by decision, stated in the design doc 1; Answered by design, with the founder's edge conceded 1; Answered by design, with a metrics caveat 1; Closed by removal, 3 October 2026 1; Conceded, stated in the litepaper 1; Conceded, stated in the design doc 1; Measured on the live node line, and the overlay does NOT… 1; Conceded, stated in the simulation 1; Conceded in part, labelled, stated 1; Fixed in the node 1; Answered with evidence for the largest body the rules allow 1; Spec fixed 1; Fixed in the proving code 1; Fixed in the spec 1; Rule fixed 1; Rule written 1; Fixed, logged 1; Answered with evidence for the test half 1; Fixed in the node and shipped, rule not yet activated on… 1; Simulation half run 1; Answered with evidence for all four 1; Written 1; Designed 1; Fixed and confirmed 1; Rolled out 1; Conceded by decision 1; Conceded, scheduled, stated 1; Conceded, contained by rule, stated 1; Fixed on a branch and verified locally 1; Answered with evidence and stated 1; Answered with evidence for PC 2 1; Answered by design and with evidence 1; Fixed, stated; restated 1; Fixed, stated; restated further 1; Fixed in part, finding bounded, stated 1; Fixed as a genesis lever, measurement owed 1.

Id Claim or criticism Status What was done Evidence
M1 The program space is tiny Decided No standing bounty. docs/bench-log.md
M2 Your own prototype is not memory-hard Conceded, stated Site/litepaper.html, Monero's idea section, the "Measured so far" paragraph, "computing items on the fly runs 4.8x slower than loading them"; What Igneum does not claim, "A memory-hard prototype on every vendor". proto-metal/TESTS.md
M3 Kaspa said ASIC resistant too Answered by design, with a correction to our own text First the correction: Kaspa did not promise ASIC resistance. kHeavyHash was designed to be friendly to specialised and optical hardware, and the Kaspa community expected chips (approximate, from memory; cite the Kaspa… design doc, "ASIC resistance" section.
M4 ProgPoW already did this and you do not mention it Conceded, stated Site/litepaper.html, precedents table row 1, "ProgPoW, as KAWPOW on Ravencoin since 2020". vendor/
M5 Your load count varies 6x between programs Fixed Generator version 2 draws exactly 16 load slots per program (spec 01 section 1.4.2, igneum-pow/src/generator.rs), and the fresh-source rule of 1.4.3 with the acceptance rule of 1.4.6 fixes the distinct count too,… proto-metal/TESTS.md
M6 Weak programs Fixed The acceptance rule of spec 01 section 1.4.6 (igneum-pow/src/accept.rs, mirrored in proto-metal/main.swift) rejects a candidate with a stale load source, a register without an injecting write, a nonce-independent… proto-metal/TESTS.md
M7 No cryptographic analysis at all Conceded, stated Site/litepaper.html, Mining section, "The hash is a lottery, not a general-purpose cryptographic hash" and "Open: no analysis of the lottery properties exists yet". proto-metal/TESTS.md
M8 Only two vendors, two programs, one day Decided A discrete AMD card (9070 XT) and a 12 GB NVIDIA card (4070) are on order for PC 2; the measurement runs on arrival. docs/bench-log.md
M9 The 10 ms CPU verification gate is unmeasured Conceded, stated Site/litepaper.html, Mining section, "Measured: 0.41 to 0.58 ms per warp on one Apple M5 Max core with the 256 MB cache"; vs RandomX "Light verification" row. docs/bench-log.md
M10 "Bound by memory bandwidth" is wrong Answered with evidence, stated Site/litepaper.html, Mining section, "bound by random memory access. docs/bench-log.md
M11 Hourly JIT on real rigs Decided The mixed-generation rig is borrowed from a farm operator later, at the HiveOS package's first test; the 9070 XT on order gives the ROCm half on PC 2. docs/bench-log.md
M12 Rentable hashrate is not just NiceHash Answered by design for finality, Conceded for the lottery Both halves true. sim/results.md
M13 Macs mine too is marketing Conceded, stated Site/litepaper.html, For miners, Hardware, "Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second" (confirmed by grep tonight; the projected-earnings half is not… docs/bench-log.md
M32 "Automatic anti-ASIC escalators" overstates what the era draw and the instruction reserve do Conceded, stated The era draw and the instruction reserve are automatic schedule changes against fixed datapaths and against human forks; against the stored-dataset chip every drawn parameter is firmware, and the defence against that… docs/analysis/horizon/algorithm.md
M33 The FPGA ceiling rests on a tFAW the JEDEC HBM2 table does not give Conceded, stated The public FPGA line carries only the measured row, 2.4 G reads/s per card and 0.30x to 0.39x of the RTX 5090 per watt (Shuhai, FCCM 2020 Fig 7; the tFAW arithmetic from ICCAD 2021 Table I), and the 11.4 G bank-bound… docs/analysis/horizon/algorithm.md
M34 The shadow size N is a constant of the binary, so the one lever against the dataset-storing chip needs a fork to move Conceded, implemented, stated The public text carries the ladder (site/litepaper.html, Mining: the six-rung genesis ladder of the latency shadow with a measured admissibility flag per rung, moved by miner signalling, never by a fork; and the X9… docs/design/latency-ladder.md
F1 Finality is attackable for the first month Rule implemented and measured; launch month simulated The harness text only: tools/finality-attacks/run.mjs names the 2/3-of-total floor in the s6 comments and criterion and in the s5 result line, where it still said 56.7%; the scenario logic is untouched. sim/
F2 The two-hour presence window is an eclipse vector Closed by rule Correct that the presence window trades safety for liveness. sim/results.md
F3 Participation grinding through the bitmap Decided The per-block vote bound and the bitmap wire bound of spec 3.4.2 items 2 and 3 are adopted for gate 3; the spec moves them from Proposed to Decided at the next spec edit. design doc Finality v2, Quorum item 2 and Checkpoints item 3.
F4 It is proof of stake with extra steps Answered by design, with the concession stated The committee's weight is blocks mined in the last 30 days. sim/results.md
F5 The headline arithmetic is misread on purpose Conceded, stated Site/litepaper.html, Finality, "an attacker producing every block on the chain, with honest miners gone" and "An attacker matching the honest network needs twenty days for a third and never reaches two thirds"; the… sim/results.md
F6 Equivocation costs nothing that matters Conceded, stated in the litepaper and the design doc True. design doc Finality v2, Checkpoints item 4 and Residual risks bullet 1.
F7 A 2-minute checkpoint on a DAG with a 1-hour merge bound Answered with evidence at 1 block/s Fair. design doc Finality v2, Checkpoints item 1 and "Three experiments before gate 3".
F8 The simulation has no network in it Conceded, stated in the simulation report Correct. sim/results.md
F9 Half the hashrate leaves and finality stalls for ten days Answered by design That table is the all-keys denominator, which the simulation recommended for safety. sim/results.md
F10 Pools hold the votes Conceded, stated Site/litepaper.html, Finality, "Pools carry their hashers' votes, so vote concentration equals pool concentration, and it is public"; Governance, "governed by the hashrate that powers it". design doc Finality v2, Residual risks bullet 3.
F11 VDFs are exotic Answered by design, with the dependency conceded. Update 7… The era VDF is in the node (spec 4.4 Implemented, behind era_vdf_activation_daa, never until the founder sets it per network), on a fixed-width integer with no C library, with the hash-chain fallback behind the… design doc Finality v2, Lottery seeds items 1 and 2, Residual risks bullet 5, "Three experiments before gate 3".
F12 Nothing outside the chain, except Answered by design Those are code dependencies, chosen because each is open source and replaceable, and none is another chain's consensus. CLAUDE.md design paragraph; design doc "Decided" paragraph.
F13 Why prove every block if every node executes anyway Answered by design Full nodes execute natively so users see state in about a second. design doc, "Proving speed on consumer GPUs" risk item and "Who needs" paragraph.
F26 "No stake" needs its one sentence: what is at stake, and what strips it Conceded, stated Site/litepaper.html, the finality section's "What is not here" paragraph and the "Igneum at a glance" Finality row carry the sentence verbatim: "No coin is staked. docs/analysis/horizon/frontier.md
P1 The 20-second shard is a number you made up Conceded, stated Site/litepaper.html, Proving, The proving budget, "Target: shard size will be set so a 12 GB card proves one shard in about 20 seconds. site/journey.json
P2 Real-time proving needs a hundred GPUs per block Conceded, stated in the litepaper, with the dial explained True, and the litepaper says a full block needs a cluster of 100 to 200 consumer GPUs, approximate. design doc "Unit economics of a proof"; litepaper "What Igneum does not claim" item 1.
P3 A phone verifies in milliseconds is a SNARK-wrapper claim Answered by design The design rule covers the claim (design 5.6 wrap, R4: the aggregated block proof wrapped once into a small curve-based proof by the aggregator) and the public text says what is and is not measured… not yet.
P4 Trustless light clients need a consensus proof you do not have Conceded, stated Site/litepaper.html, precedents table row 6, "The consensus proof that makes the checkpoint self-verifying is phase two"; Building item 2, "Light clients". design doc, hostile review table rows "Slashing an external prover" and "One-proof light clients".
P5 EVM "unchanged" on a DAG is false Closed by spec Correct. design doc, hostile review table row "EVM semantics on a DAG".
P6 The proving market is tiny Conceded, stated Site/litepaper.html, The problem, "a supplier whose marginal cost is close to power"; "cheapest supplier" and "lowest cost" absent from the page (grep, tonight). design doc "Market size, honestly" and "Existing prover networks" table (labelled from memory).
P7 A soundness bug in SP1 is a consensus failure Conceded, stated Site/litepaper.html, Abstract, "Writing new code, including an emergency fix to the proof system, is the one thing that takes a person"; Proving, "no node accepts a block with a wrong state root". design doc "Proof system churn" risk item.
P8 Fastest prover wins all the shards Closed by rule Fair, and the lottery/proving separation does not by itself fix it. design doc "Proving speed on consumer GPUs" risk item and Finality v2 "Fees".
P9 Shard griefing Decided The parameter table's values are the phase 4 devnet's starting values (8 assignees, a 25-s exclusive window, a 120-s job claim timeout, no shard bond, the external job bond set on the devnet); the devnet measurement… design doc, Security model table row 3.
P10 External jobs are paid off-chain, so where is the burn Conceded, stated Site/litepaper.html, Economics, "Outside customers pay in their own currency on their own chain at launch; settlement in IGN with a 10% burn follows when the proof bridge lets Igneum see the payment"; the route table… design doc "The first six months" risk item and hostile review table row "Slashing an external prover".
P24 "20 percent of emission to provers" without the caveat that consensus does not verify the proof Conceded, stated Site/litepaper.html, Economics, the 20% proving-pool row carries the caveat: consensus does not yet verify the carried proof, it checks the record's statement against native execution and its signature, so today a… docs/analysis/horizon/consensus-security.md
P25 Unclaimed pool credit is stranded in the escrow Conceded, stated Site/litepaper.html, Economics, the 20% proving-pool row carries the note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven… docs/analysis/horizon/economy-and-utility.md
E1 Hard cap plus burn is a security budget cliff Conceded by decision, stated in the design doc True, and the design doc records the choice: "A 1% tail is the Monero model and the safer choice for security on its own." The argument for the cap is that Igneum miners keep earning from in-chain proving fees and… design doc "Decision: hard cap".
E2 Half the coins in two years is an insider schedule Answered by design, with the founder's edge conceded The schedule (1 billion a year halving every two years, 30-day ramp from 10% to 100%) is public, fixed at genesis and the same for every miner. litepaper "Supply" and "Fair launch, announced".
E3 The 20% developer share enables wash gas Answered by design, with a metrics caveat The base fee is burned in full, so every wash transaction loses its whole base fee. design doc Finality v2 "Fees"; litepaper "What a builder gets for being early".
E4 5% of gas to the dev fund is a tax Closed by removal, 3 October 2026 There is no development fund. spec section 5.5; design doc "No development fund, so nothing to fight over".
E5 "Not one coin to a founder" is false Conceded, stated Site/litepaper.html, Economics, "No fund, no foundation, no fee to the team", "1 block in 100 pays the project"; site/index.html, Economics, "The one payment to the project is the Ember software's optional 1% dev… design doc "No development fund, so nothing to fight over".
E6 Two-year halvings bleed hashrate Conceded, stated Site/litepaper.html, Economics, Security after the subsidy, "The schedule is a bet, not a measurement: a halving halves emission income overnight if price and fees do nothing", with Kaspa's reduction marked… none; decision in design doc "Supply".
E7 No stablecoin liquidity without a trusted bridge Decided Correct. design doc, hostile review table row "One-proof light clients and committee-free bridges".
E8 Founders seeding the DEX is market making by insiders Conceded, stated True and stated in the litepaper. litepaper "Liquidity from the people who are there".
E19 "Proving: a second income" without the arithmetic of how small it is Conceded, stated Site/litepaper.html, "For miners", under the three-streams table: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block x 7,200 blocks; the tracker figure is a… docs/analysis/horizon/frontier.md
E20 "Proofs at the cost of power" is the electricity, not the price Conceded, stated Site/litepaper.html, The problem ("a supplier whose electricity cost is close to power and whose price is the subsidy it forgoes, which falls as the network's hash grows"), Building on Igneum ("Proofs priced by the… docs/analysis/horizon/economy-and-utility.md
E21 The dev fee is 1 percent of the producer share, and the funding plan's ceiling took all rewards Conceded, stated Site/litepaper.html, the payment-routes row 6 and the Ember section read "default-on, switchable, 1 percent of the producer share"; docs/plans/funding.md section 4's ceiling is 1 percent of the producer share, USD… docs/analysis/horizon/economy-and-utility.md
G1 No cryptography team Conceded, stated Site/litepaper.html, Questions miners ask, "reviewers will be named and paid before gate 3"; What Igneum does not claim, "A cryptography team. design doc "Team" paragraph.
G2 An AI designed this Conceded, stated Site/litepaper.html, cover, "Method one founder with AI systems"; Who are you?, "One founder, pseudonymous, working with AI systems". .claude/agents/
G3 Who are you Decided No team page for now; the litepaper says the team is pseudonymous and names no team page. site/journey.json
G4 No admin keys, except in everything that matters Conceded, stated The home page was redrawn as one statement, the live scene, three facts and the downloads, so the tile "admin keys in consensus" is no longer on site/index.html; the sentence stands on site/litepaper.html,… litepaper "Governance".
G5 No multi-client Conceded, stated in the litepaper True at launch. litepaper "Governance", last bullet.
G6 Stratum v2 does not make pools unable to censor Conceded, stated Site/litepaper.html, Governance, "Pools can be bypassed on transaction choice". none in repository.
G7 The one-click app is an update key over the network Decided Correct. not yet.
G8 Governance by hashrate is governance by two pools Conceded, stated in the design doc True in the same way it is true on Bitcoin, where miner signalling activated SegWit and Taproot. design doc Finality v2, Residual risks bullet 3.
G15 Three signalling thresholds, four numbers across the documents Conceded, stated One sentence in site/litepaper.html, Governance ("Miners set what genesis leaves open") and Mining ("Miners hold the switch"): miners signal three things at three thresholds, 60 percent of blue blocks over two weeks… docs/analysis/horizon/economy-and-utility.md
C1 vs Monero: GPUs were excluded on purpose Answered by design Monero chose the CPU for egalitarian reasons and accepted botnets as the price. litepaper "For miners", hardware paragraph.
C2 vs Monero: "no chip in seven years" is not proof Conceded, stated The home page no longer carries the RandomX paragraph; "since 2019 (approximate)" and "precedent, not proof" stand on site/litepaper.html (vs RandomX, Mining). none.
C3 vs Kaspa: you misrepresent them Conceded, stated Site/litepaper.html, The problem, "Chips arrived, as on Kaspa, whose hash was designed to welcome them"; Speed, "Kaspa has run in production since 2021 (approximate), forked from rusty-kaspa"; precedents row 5,… none in repository; vendor/rusty-kaspa to be cloned and cited.
C4 vs Kaspa: a finality overlay changes GHOSTDAG's guarantees Measured on the live node line, and the overlay does NOT… A NEW SERIOUS FINDING (5 October 2026 sweep; owner: cryptographer and consensus engineer, decision owner the founder). sim/results.md
C5 vs Ethereum: you compare inclusion to finality Conceded, stated Site/litepaper.html, Speed, "Inclusion is not confirmation on either chain". litepaper "Speed".
C6 vs Ethereum: every one of your components is a research project Conceded, stated Site/litepaper.html, Roadmap, "the combination is the risk the gates price" and "Dates slip. litepaper "Roadmap".
C7 vs Bitcoin: hashrate that follows price is the design, you penalise it Conceded, stated in the simulation Correct. sim/results.md
C8 vs Ergo, Ravencoin, Conflux: GPU mining has a home Conceded, stated Site/litepaper.html, The problem, "Ergo, Ravencoin and Conflux still mine on GPUs at a fraction of the 2022 fleet (approximate)"; precedents row 3 names Conflux. none in repository; to be cited from their repositories.
C9 vs Aleo: you will centralise the same way Closed by rule See P8. design doc "Existing prover networks" table, Aleo row.
C10 vs Boundless and Succinct: you cannot bid there without their tokens Conceded, stated Site/litepaper.html, Proving for everyone else, "Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation)". design doc "Existing prover networks" table, labelled approximate.
C11 vs everyone: "firsts" that are not Conceded, stated Site/litepaper.html, precedents table, "We know of no chain that combines them"; Building, "that we know no other EVM chain offers". this ledger.
C12 vs Monero: you borrowed the hash idea and left out the point Answered by design Transactions on Igneum are public, as on Ethereum. CLAUDE.md rules (privacy rejected).
L1 It is a security under Howey Open Only the founder's decision with counsel settles it; counsel engaged since 6 October 2026 (decisions item 6). design doc "Legal" paragraph.
L2 Financial promotion rules Open Only the founder's decision with counsel settles it; the text half is stated (the schedule facts above). none.
L3 GoDaddy domains are a seizure risk Decided The nameserver move to deSEC in one sitting with every domain's Vercel verification checked afterwards; a non-US registrar in December 2026 when the transfer lock ends. CLAUDE.md "Domains".
L4 Paying testnet miners real money is a payment before launch Open Only the founder's decision with counsel settles it. design doc "The first six months".
L5 Trademark Answered with evidence The clearance search is recorded in the repository as the entry asked, docs/legal/trademark-search-2026-10-03.md (3 October 2026, one verdict per register: EUIPO RISK, IGNIUM EUTM 018212492 live in classes 36 and 42;… none.
L6 A permissionless job market paid in dollars is money transmission Answered by design At launch jobs are paid on the customer's chain, in the customer's asset, by the customer's contract, to the prover's address; Igneum operates no custody and takes no cut off-chain. design doc "The first six months".
X1 "Reproducible from the repository" and the repository is private Conceded, stated Site/litepaper.html, vs RandomX "Track record" row, "The specification, reference hash, test vectors and simulators are public now (github.com/igneum-network/spec). site/index.html
X2 "Get the miner" with no miner Conceded, stated Site/index.html, hero button "See the miner"; the Mine section's download buttons carry the shipped devnet build's version and size (v0.3.9) beside "Public testnet: not yet open; the devnet build is here for people… site/index.html
X3 "Proven by fire" when nothing has run Conceded in part, labelled, stated The proofs feed moved to the litepaper's proving section with the home-page redesign and reads "Live rows arrive with the public testnet. site/index.html
X4 Thirteen months with one founder Conceded, stated The roadmap is aggressive and every phase is a gate that can repeat or stop the project, which the litepaper says. litepaper "Roadmap"; design doc "Team".
X5 1,000 independent miners is a Sybil number Decided The independence definition as written, with the silent-fleet addition (a key with no fingerprint counts as its own class only when its address is in an autonomous system no other key uses); the observer columns on… site/journey.json
X6 The one-click app is a honeypot vector Decided Correct on all three. not yet.
X7 No community exists Conceded, stated This ledger's submission line names hello@igneum.network and the spec issues route; site/litepaper.html last paragraph and the footer on every page carry both. site/index.html
X8 Exchange listings as a roadmap item Conceded, stated The home page's journey is no longer shown (the inlined feed remains in the page source); the sentence "No listing is arranged, promised or sought by the project" stands on site/litepaper.html Roadmap phase 6 and in… site/journey.json
X9 Launch hashrate will be trivial Conceded, stated Site/litepaper.html, Finality, "In the chain's first 30 days no checkpoint locks at all"; Fair launch, "The first 30 days of mainnet run on proof of work alone". sim/results.md
X10 Five milestones in one day Conceded, stated Site/index.html, journey section, "The log below is the engineering log's dated entries, newest first. site/journey.json
M14 A pulsed rental against the block-count DAA buys weight at a discount Answered with evidence , ledger close round 1: M14 and F14 the 50x pulse against a lagging retarget inside the finality simulator, both W2 forms"). sim/difficulty/devnet-2026-10-03.csv
M15 A header with any past timestamp or any claimed DAA score makes the node build a 256 MiB cache Fixed Correct. docs/fork-divergence.md
M16 The 256 MiB cache fits on a die, so the recompute attacker is compute bound Answered with evidence On the 5090 the recompute attacker with the cache inside the 96 MiB L2 (the SRAM emulation, 64 and 32 MiB masks, bit-exact against the stored construction) runs at 33.9 Mhash/s against 132.2 honest for the same… proto-metal/MEMHARD.md
M17 Every ahead-of-time miner stops at the epoch boundary; whoever compiles in process mines alone Fixed And measured on the live devnet at the DAA 3,600 boundary (docs/bench-log.md, "first hourly program swap"): prepare sent 449 DAA before the boundary; Metal compiled in 82 ms, CUDA ran nvcc in the background in 1,285… proto-cuda/windows-miner/start-mining.ps1
M18 The per-hash random data path is a one-bit select Conceded, stated Site/litepaper.html, Mining table "Every hash" row, "The one-bit select inside the maths costs a chip nothing and is not a defence"; vs RandomX "Random program" row, "the 128 dataset addresses change with the nonce". site/litepaper.html
M19 The census that justifies the generator rule has blank cells, and the spec still carries the free load count Fixed Correct. docs/analysis/weak-program-census-2026-10-03.md
M20 Pruning proofs are checked with the kHeavyHash stub Fixed in the node Correct. docs/fork-divergence.md
M21 GHOSTDAG k is Kaspa's table value for Kaspa-sized bodies Answered with evidence for the largest body the rules allow , ledger close round 1: M21 block propagation with bodies at the mass limit, k re-derived"); the red rate under such bodies is not measured. docs/design/execution-layer.md
F14 Weight in blocks over a window in blocks under a lagging retarget Answered with evidence , ledger close round 1: M14 and F14 the 50x pulse against a lagging retarget inside the finality simulator, both W2 forms"). sim/results_v2.md
F15 Merge depth is not the reorg bound; the finality depth is Spec fixed Spec 2.1 names the finality depth as the reorg bound and merge depth as a merge limit only, spec 3.8 and 3.9 tell exchanges to wait 12 hours of past-median time when finality_active is false, and the simnet reorg… the files above.
F16 A lock can become uncertified after a heal Decided Option B, a verified certificate is never withdrawn (spec 3.11.4); the 3.5 paragraph is replaced by 3.11.4's text after c4-fix merges, finality_conflict and the finality_active clear go into the node, the forced… spec 3.5, 3.9.
F17 Keys are free and the official client mints eight per card Decided The client defaults to one vote key per machine, identities share it (spec 3.4.2 item 4); the bitmap bound as item 3. proto-cuda/windows-miner/start-mining.ps1
F18 "A silent minority cannot freeze finality" is false under the floor Fixed Correct. sim/results_v2.md
P11 The native-execution veto makes block validity depend on the node's current selected chain Fixed Spec 7.2 item 5 and docs/design/execution-layer.md 5.5 and D12 are relative to the carrying block's own selected-parent chain; the two-node reorg test is a row in the design document's 8.5. docs/design/execution-layer.md
P12 An aggregator can name itself as every prover Fixed in the proving code Every shard proof's public values carry the prover's payout address (ShardOutput.prover), the aggregated block proof commits keccak over the provers in shard order and the shard program's verifying-key hash… docs/design/execution-layer.md
P13 The litepaper still claims shards with a bond Fixed Site/litepaper.html, Proving, "How a block gets proven". site/litepaper.html
P14 Two definitions of the proving base fee, and a quote that cannot know the ratio Fixed in the spec One definition. docs/design/execution-layer.md
P15 RPC blocks are segments, so gasUsed can exceed gasLimit Fixed on a branch, pending merge Igneum/exec/src/rpc.rs reports gasLimit as k x BLOCK_EXECUTION_GAS_LIMIT for a k-block segment (k = the record's mergeset length, at least 1), beside the segment's gasUsed, so gasUsed <= gasLimit holds for an… docs/design/execution-layer.md
E9 The specification's year is 365 days; the code's is 365.25 Fixed Spec 2.5 follows the code (365.25-day year, 63,115,200-s halving, 31.688 IGN per DAA second, 8 decimals noted under O-2.6). consensus/core/src/igneum.rs
E10 Reds are paid in the code and "more blocks never means more coins" is false Fixed Spec 2.5 says reds inside the DAA window are paid to the merging miner (80%) and the pool (20%), that E is paid per block so coins are blocks times E under the controller's rate, and that the cap is unaffected;… docs/review/round-3-2026-10-03.md
E11 The homepage burns job fees at launch Fixed Site/index.html, "Proofs sold to other chains" caption and the tile now read "phase two"; the quoted paragraph had already left the page when the homepage was trimmed (commit a commit). site/index.html
C13 Monero's seven years do not price a 256 MiB SRAM die Conceded, stated Site/litepaper.html, What Igneum does not claim, "they say nothing about the price of a chip with the 256 MB cache on its die, and that price is a cost model, not a measurement". none beyond M16.
L7 "Where the price comes from" Fixed Heading "Where fees go" and the sentence deleted, site/litepaper.html Economics. site/litepaper.html
L8 Third-party names as implied outcomes Conceded, stated Site/litepaper.html, Questions builders ask, "whether it is issued is Circle's decision"; Canto and Blast absent from the page (grep, tonight). site/litepaper.html
G9 The release-key the team is one person, and a lost key cannot be revoked Rule fixed Spec 8.2 item 5, rotation signed by the current key and revocation signed by the previous key (a pre-signed certificate for K0), both published in a block; item 2 moves the policy to before the client ships and adds… spec 8.2.
G10 The signalling default on first run Rule written Docs/spec/08-client-security.md 8.3 item 2 now ends: on first run there is no last choice, the client signals nothing until the user chooses, and the interface shows that nothing is being signalled. docs/spec/08-client-security.md
X12 Tonight's numbers are quoted before they are logged, and the worker efficiency gap is unexplained Fixed, logged Bench-log "5 October 2026 (night), ledger close round 1: X12 the 3 October devnet run from its record"; the launcher half (the eight processes' summed status) stays open until the PC's log is read. sim/difficulty/devnet-2026-10-03.csv
M22 The ASIC challenge has no scoring rules, and 2x is not the economic line Decided No bounty, so no bounty terms; M22's metrics (hashes per second and per joule per program over at least 100 epochs as a distribution, capital cost per unit of hash rate at a stated volume, the longevity term, the… M1, O-1.17, spec 1.13 and 1.16, M16's arithmetic.
F19 Old vote keys can be bought; fresh hashrate cannot buy weight Answered with evidence A bought key is worth the blocks it holds and nothing more. sim/results_v2.md
F20 During a finality pause the program must keep advancing, and nothing says which guarantees survive Answered with evidence for the test half , ledger close round 1: F20 finality pause under a 45% silent set through four epoch boundaries"); the gate-3 wording of the four guarantees (O-3.16, O-4.3) stays a decision for the founder. spec 4.3 (O-4.3), 3.3.1, 3.5, 3.7 item 2, 3.9.
F22 Certificates carry 8 to 10 of 12 votes on a healthy network, so locks sit a hair above the floor Fixed in the node and shipped, rule not yet activated on… True as measured, and the cause is not a cut-off at all: the node builds the certificate the instant the votes it holds meet Q3, and carries that one. infra/cloud-devnet/results/2026-10-04/partition-sin-20261004-140305/partition.md
P16 The proving gate can be passed by shrinking the shard Decided A 12 GB NVIDIA card (4070) is on order for PC 2; O-7.1 runs end to end on it when it arrives, inside the phase 2 gate. docs/bench-log.md
P17 Interfaces must show four states, and the design shows three Fixed on a branch, pending merge a fork a commit (a commit rebased onto the 0.3.11 fork tip a commit in round 3), suite igneum-exec 16 of 16 on the Mac (labelled a Mac run), the O-7.2 conformance run PASSED on a fast-time 3-node network (bench-log… execution-layer 2.3, 2.4, 8.2; phone-app 3 and 9; spec 3.9, 10.1.
E12 Selfish operators under a price shock Simulation half run No backlog in any scenario, every block proven within 60 s in every hour, hash troughs at 82% of its pre-event level under b and 75% under d (80% at day 30), 10% of cards off under b… spec 5.1, 5.3, 7.2; execution-layer 4.3, 9.1 R8.
E13 One diagram per payment route, or operator income and protocol income blur Conceded, stated Site/litepaper.html, Economics, "Every payment route", six rows (emission; base fee; priority fee; external job at launch; external job after the proof bridge; the official client's dev fee as operator income),… docs/commercial/prover-customer-brief.md
E14 No funding table Decided The funding table stays internal until counsel has read it; one public sentence in the litepaper names the unfunded lines (the second client, the external reviewers, the bounty before escrow). E4, E5, G1, G5; fud-fixes rows 47, 50, 71.
E15 The security budget through successive halvings with low fees and no external demand Decided The 4,000,000,000 IGN hard cap stays absolute and there is no tail emission. spec 2.5, 5.1 to 5.4; E1, E6.
G11 Publish the inspectable components now, labelled experimental Decided The specification subset is public as igneum-network/spec (docs/plans/public-repo.md), labelled; the node fork, the proving code and the harnesses stay private until the benchmark. docs/fud-fixes.md
X13 One paying customer for a stated reason Decided The paid pilot stays in phase 5, the phase 4 gate stays the signature, nothing moves earlier before counsel answers L4. site/journey.json
X14 Concentration is unmeasured in four places Answered with evidence for all four , ledger close round 2: X14 signing concentration from block payloads"); the independence definition stays the founder's (X5). X5, F10, P12, spec 9.4.2.
X15 Remove the founders from a test network and show what continues Answered by design The design rules the sentence rests on are in force (every node ships a VDF evaluator, spec 4.5; the seed list ships in the client, spec 10.6; no project-run service sits in consensus, no stake, no fee to any team,… site/litepaper.html
X16 An evidence page with four labels Written Docs/evidence.md, one row per public claim with five labels (tonight, counting the label column of the claims table: designed 9, implemented 8, tested by the team 26, reproduced externally 3, reviewed independently 2). docs/bench-log.md
X17 The miner app must show net earnings and keep jobs away from keys Designed Spec 8.8 and phone-app 4.1; measurement O-8.2 and the escape test O-8.3 scheduled for the phase 4 devnet. site/litepaper.html
P18 The mempool queues transactions no block can carry Fixed Correct, and low: the queue slot was reserved against the sender's funds, so it was self-limited. docs/bench-log.md
P19 An over-budget proving transaction runs for free, every time, and blocks its sender Fixed Correct, medium. docs/bench-log.md
P20 The SP1 GPU client panics on shutdown and the compressed stage waited ten minutes Fixed and confirmed The buffered save closed the gap, the core proof finished at and the compressed stage started at; shard timings repeated within 0.3 s (core 9.1 s, compressed 10.5 s); a guest that returned 0 bytes on the second run was… docs/bench-log.md
M23 Forge timestamps inside the rules and the controller mines you a 10x difficulty for free Fixed Correct on every point, and measured first by our own attack run (sim/difficulty/attacks/README.md, scenarios 3 and 7): in the simulator a 50% forger took the block rate to 0.12 (earliest stamp) and 0.56 (latest) of… docs/bench-log.md
P21 The SP1 proof is not what consensus checks in proving v0 Decided Proving v0 (every producer verifies off the consensus path) through the public testnet; the in-consensus verifier is the execution engineer's plan item for after it; the litepaper sentence labelled Open stands. none named
P22 The rewards and payouts are inputs to the shard proof, not outputs Answered by design The design rule that contains it is in force, spec 7.7 item 6 and design 5.5: the rewards and payouts a shard statement carries are checked against every node's own consensus derivation, so a proof over any other list… none named
M24 Your two-lane controller oscillates for an hour when a second miner joins mid-epoch Rolled out Rule v2 activated on the live devnet at DAA 33,000 by the height switch after a 12-node cloud rehearsal (settle 157 to 272 s, no swing); node 1, the seed, the observer and the three app machines crossed the height on… sim/difficulty/records/live-2026-10-04.csv
D1 Your users are a gate, not a fact Conceded, stated Correct on the count and on the definition. docs/bench-log.md
D2 The app share pays nothing Conceded, stated Site/litepaper.html, Building, Why build here, "a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year"; Canto and Blast absent from the page (grep, tonight). docs/design/developer-adoption.md
D3 Proof of work in 2027 is a perception cost you cannot measure Conceded, stated Site/litepaper.html, What Igneum does not claim, "A label that costs nothing. site/litepaper.html
D4 No dollar, no DeFi Conceded by decision , restated here for builders. docs/review/round-3-2026-10-03.md
D5 I cannot debug a revert Conceded, scheduled, stated Site/litepaper.html, What Igneum does not claim, "A chain you can debug today. docs/design/execution-layer.md
D6 A forged job result reaches my contract and nobody vetoes it Conceded, contained by rule, stated Site/litepaper.html, What Igneum does not claim, "A veto on job results. docs/design/execution-layer.md
X23 One shipped key is an administrator channel to the founder's PCs Fixed on a branch, pending merge Three tiers in relay/lib/guard.mjs (authVia): the console token (header or the phone page's path), the relay's own key (RELAY_KEY: reads and reports, never task, run, name, role, secret, delete), and… docs/review/round-4-2026-10-04.md
X24 The relay token rides in the URL on every request Fixed on a branch, pending merge Every client and Mac tool calls /api/relay?fn=<fn> with x-relay-token (and x-igneum-key) as headers: igneum-agent.ps1 and send.ps1 (Api-Url), agent.sh and send.sh (through a 0600 curl config file, -K,… tools/relay.mjs
X25 The PC agent installs itself at every logon, at highest privilege, on every start Fixed on a branch, pending merge Igneum-agent.ps1 calls Arm-Restart only on the two paths that end in shutdown.exe /r (a task that printed RELAY-REBOOT on its own line AND was queued with --reboot or --reboot-continue), sets… relay/clients/igneum-agent.ps1
X26 The feed is a permanent transcript, and it holds the dl token by design Fixed on a branch, pending merge Retention 30 days (relay/lib/handler.mjs expire: `DELETE... relay/lib/handler.mjs
X27 The relay has no clean rotation and no sender binding Fixed on a branch, pending merge A per-machine secret (64 hex, node tools/relay.mjs secret PC1: written to ~/.config/igneum/relay-machines/PC1 at 0600, its sha256 bound on the relay with POST secret (token only), carried to the PC as… relay/README.md
X28 Relay hygiene, minor Fixed on a branch, pending merge The remaining points. lib/wake.mjs
G12 The PoW schedule comes from the environment on every network, including mainnet Fixed . the files above.
G13 The update signature covers binaries that nobody signed Fixed on a branch and verified locally The chain already on master was read end to end and run, not asserted. packaging/windows/push-inputs.sh
G14 Secrets and identity in the history of a repository with a public date Decided TZ=UTC in every commit path the tooling owns: tools/ship-app.mjs (git runs with env: { TZ: 'UTC' }), packaging/ota/publish-jobs.sh (export TZ=UTC, found by the class check), tools/repo/fresh-repo.sh… tools/ship-app.mjs
X18 Two nodes with two override files connect, and only some mismatches fork Fixed . the files above.
F23 The equivocation ban is node-local, so honest nodes refuse each other's certificates Fixed . the files above.
F24 A checkpoint determination is never revisited Fixed . the files above.
F25 The fast-time harnesses cannot start a node, and the timestamp probe tests the old rule Fixed Correct, measured. rt/logs/fa_s8/n0/node.log
X19 Operational knobs and silences in the shipped node Fixed on a branch, pending merge The node half, fork commit a commit. protocol/flows/src/flowcontext/clock_skew.rs
X20 Cold-sync checkpoint determination is indices times chain length Fixed on a branch, pending merge Consensus/src/processes/finality.rs on_virtual_changed resolves every index the sink can determine in ONE descending walk of the selected chain (chain_blocks_at, targets highest first), where it walked from the… consensus/src/processes/finality.rs
M25 The miner takes the day length from its environment, and the schedule global can tear Fixed on a branch, pending merge Correct. igneum/miner/src/main.rs
M26 The interval fault guard freezes its baseline and loops Fixed IntervalGuard builds its baseline from the healthy intervals of the current worker process (a moving average, two intervals before it can trip) and forgets it when the worker restarts; the STATUS line is printed on a… docs/bench-log.md
M27 A flapping node makes the worker rebuild once per template Fixed Correct. the files above.
M28 The kernel text is bound only to its own directory Fixed on a branch, pending merge Correct. proto-cuda/nvrtc/packfile.h
X21 A wrong program burns power with a green rate Fixed Correct. the files above.
X22 Worker restart paths, minor Fixed on a branch, pending merge The four remaining paths. app/igneum-app/src/engine.rs
E16 The 20% pool is burned on the live chain, and the text says it pays provers Answered with evidence and stated Correct for the live devnet-v4 line. docs/review/round-4-2026-10-04.md
L9 "100% to miners and provers", "0% anyone else", and no word that devnet coins have no value Conceded, stated Site/index.html, site/miner.html and site/wallet.html, a line beside every download control, "Devnet: coins have no value and the chain may be reset."; site/index.html Economics tiles, "of emission to miners… the files above.
M29 The litepaper's app paragraph describes an app that does not exist Conceded, stated Site/litepaper.html, For miners, "One click, for everyone else", rewritten to Ember 0.3.9 from app/igneum-app/ui/index.html (hash rate, blocks found, node, next program, finality votes, the proving tile, the devnet… ui/app.js
M30 A block or transaction flood grows the 0.3.4 node by hundreds of megabytes in a minute Fixed Measured, cause not yet isolated. docs/bench-log.md
M31 The 0.3.4 node cannot produce a block template on mainnet, testnet or simnet parameters Fixed Measured on the execution-layer attack network (tools/exec-attacks/net.sh runs --simnet with no override): three nodes up, 0 blocks, every template refused with that line (docs/review/redteam-2026-10-04.md row 27). rt/logs/exec_b/miner_node1.log
E17 Unlogged inputs behind the economics, minor Answered with evidence for PC 2 RTX 5090 honest 132.2 Mhash/s at 326.6 W median, 3,060 MHz, 50 to 54 C, 100% utilisation (0.40 Mhash/J); 346.9 W at 8 warps per block; the inline settings 415.7 W and 431.0 W (the power limit). docs/review/round-4-2026-10-04.md
E18 The dev fee is a protocol fee with better PR Answered by design and with evidence The fee exists and is disclosed; the rest is wrong in three places. docs/design/miner-dev-fee.md
X29 Host and file hygiene, minor Decided The curl part: infra/gpu-bench/upload.sh writes header = "x-igneum-key:..." to a 0600 temporary config and calls curl -K; proto-cuda/windows-app/upload-log.bat and proto-cuda/windows-miner/upload-log.bat do… infra/gpu-bench/upload.sh
X30 The live page and the bench page exposed operational detail Fixed Ac89a37 and a commit (a scrubbed copy, the build fails on any private string), a commit (none of the three in the public API), a commit (the menu). the commits above.
X31 The public testnet dated "August 2027" on the site Fixed, stated Every mention of the month is gone from the site. docs/plans/testnet-go.md
X32 The roadmap carried calendar months beside a testnet that is weeks away Fixed, stated Every calendar month is out of the roadmap. site/litepaper.html
X33 The public benchmark dated "January 2027" Fixed, stated Both sentences read "The public benchmark with a leaderboard ships with the public testnet." (site/litepaper.html, For miners and Questions miners ask). site/litepaper.html
X34 RandomX described as chip-free Fixed, stated Four sentences corrected, each with the X9 as the stated fact and its date; every sentence that only names the technique stands. site/index.html
X35 The class v4 chip headline stated as one number, 2.1x Fixed, stated; restated The served texts give the floor and the premium at the 5090's measured knee: 2.1x per joule with a core as good as a the team (k = 1), 3.4x with one three times better (k about 0.33), no core below about 1.8 pJ per op… docs/design/latency-ladder.md
X36 The X9 described as a shipping chip Fixed, stated; restated further The X9's claimed ratio is against a CPU core, not a the team, so the texts no longer use it as a pessimistic chip core; every served sentence says so; the pin for X36 moved. site/index.html
X37 The class v4 energy premium is a cost the user pays, not a line in a model Answered with evidence Measured on the RTX 5090, 145 W of premium unlocked and 82 W at the knee; the RTX 5080 at stock 84 W, its grid running; the team identity says the premium needed for 2x at k = 1 is 103 W at the lock and a premium of… docs/plans/counter-asic-3-status.md
N1 A 0.3.15 node on the live file wrote blocks every 0.3.14 node rejected Fixed The class v4 signal (PROPOSED, docs/plans/counter-asic-3-node.md section 6) is the producer's object version in the high byte of the header version; the first 0.3.15 build stamped it from the binary alone, so on the… infra/fast-time/node-compat.mjs
N2 Any peer could crash any pruned node with a sync request below its retention Fixed SyncManager::antipast_hashes_between (the IBD headers path, RequestHeaders) unwrapped the GHOSTDAG reads of the requested low block and of every chain block of the walk; a pruned node holds no GHOSTDAG data below… unit test a_sync_request_below_retention_is_an_error_not_a_panic (a chain of six headers, the genesis's GHOSTDAG…
P23 An unwound transaction leaves the node's view until its sender resends it Fixed on a branch, pending merge a fork a commit (the P23 commit, on the merge of ledger-fixes and ledger-fixes-2 onto the 0.3.11 fork tip a commit); EvmPool::on_chain_removed (igneum/exec/src/pool.rs) and ExecService::requeue_unwound… igneum/exec/src/pool.rs
AP-F8-1 A load whose source was last written by or, mul or mulhi makes a cross-hash hot set Fixed in part, finding bounded, stated Class v4 sub-version 3 (igneum-pow a commit, the audit-freeze tag) is frozen with the dataflow rule, the shared-operand rule, the 0.98 ratio and the total draw; the in-house pass's F8 re-gate reads 60 of 64 seeds under… docs/analysis/ca3-v4-uniform.md
GF1 A post-quantum signature scheme would need a hard fork, and every vote key is a public BLS12-381 point Fixed The byte costs nothing now and a fork later. none named
GF2 A vote key cannot move: a miner who changes keys re-earns 30 days of weight, and so does the post-quantum migration Fixed The successor inherits the window, not a fresh one, so a key rotation costs no weight and the migration of GF1 is one item per key. none named
GF3 A 256 MB on-chip cache makes the lottery hash 2 to 3x cheaper for the card that has it, and the cache size is a constant Fixed as a genesis lever, measurement owed Consumer LLC is 96 to 128 MB today and datacentre 256 MB (chip-model-v3, approximate), so the shortcut is a datacentre card's today and a consumer card's in a generation or two. none named
GF4 The class-group VDF falls to the same quantum computer Conceded, stated Site/litepaper.html, What Igneum does not claim, "A delay function that outlives a quantum computer. none named