igneum/docs/design/developer-adoption.md
igneum-labs 03ec2833b6 Windows launcher: brace a variable before a colon (second PowerShell parse error, found on PC 2)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-04 10:02:41 +00:00

53 KiB

Developer adoption: why a builder deploys on Igneum as well as Ethereum

4 October 2026. the project lead's ask: "we need a solid 'why people will choose to bring apps and features to our network as well as eth'. we need to solve this perfectly." This document is the mechanism-level answer and the plan to make it true. Every claim is grounded in a file in this repository or a cited source with a date. Figures from memory are labelled approximate. Nothing here is a prediction of the coin's price and nothing is a sale of anything.

Sources read: docs/spec/07-execution.md (7.1 quoted gas price, 7.5 the pgas cap), docs/spec/05-fees-and-economics.md (5.2 the priority fee split, 5.5 no development fund), docs/spec/03-finality.md, docs/spec/09-pool-protocol.md, docs/spec/10-light-client.md, docs/design/execution-layer.md (4.1 to 4.5 gas and attribution, 6 the proving precompile, 7 light clients, 8 tooling, 10 what devnet v3 implements), docs/design/payment-routes.md, docs/analysis/economy-2026-10-04.md, docs/analysis/security-budget.md, docs/plans/funding.md, docs/commercial/prover-customer-brief.md, docs/bench-log.md (3 and 4 October 2026 entries), docs/evidence.md row 22, docs/fud-ledger.md sections 4 and 6, site/litepaper.html, site/index.html, site/verify/core.js and verify.js, site/journey.json.

The one-paragraph answer. A builder will not come for "EVM compatible and faster"; section 1 shows that pitch has never retained anyone. Igneum has three things Ethereum and its L2s do not have, and only one of them is worth money on day one. The app share (2a) is a property, not an income: at devnet fee levels it pays a 100,000-gas call about four ten-millionths of a dollar. The proving precompile (2b) is the real product: proofs of arbitrary computation from cards that are already running and paid by emission, verified by the chain's own proof, at a floor price three to four orders of magnitude under today's prover markets, with the market price unknown until phase 4. The miner base (2c) is the only user base a new chain has ever had that did not have to be paid to arrive, and it is the beachhead because miner-shaped apps have customers before any consumer does. The bridge (3) is what makes "as well as" rather than "instead of" true, and it is trustless only in phase two. The cold start (4) is real and the plan is miners first, verifiable compute second, consumers last. The developer-experience gaps (5) are listed with an order. Ten reasons to say no (6) are answered or conceded, and the conceded ones are in the ledger as section 9.

1. The problem, stated against the evidence

"EVM compatible and faster" has been the pitch of every EVM L1 and L2 since 2021. Here is what each distinct variant of it bought and what it kept. Figures are from the sources named, on the dates named; where a source is a secondary summary it is labelled.

Chain The pitch, and the incentive What it bought What it kept Sources
Canto (L1, Aug 2022) "Contract Secured Revenue": 20% of the transaction fees of a registered contract to an NFT the deployer holds, claimed through the Turnstile contract. The closest precedent to Igneum's app share TVL peaked at over $200M in March 2023, approximate (secondary) Lending TVL $1.44M, DEX TVL $248K, CANTO at $0.0025 with a market cap of $1.55M on 4 October 2026 (DefiLlama via search). An L2 migration was announced in September 2023 and reversed in March 2024 docs.canto.io CSR page; CoinDesk 30 May 2023; DefiLlama chain page via search 4 Oct 2026
Blast (L2, Feb 2024) Native yield (ETH and stablecoin yield passed through) plus Blast Points and Blast Gold convertible to an airdrop TVL over $2B in June 2024; revenue about $3.5M in June 2024 TVL $32M and monthly revenue $1,793 in September 2026; the team announced the shutdown on 2 October 2026: "the ongoing costs of maintaining Blast exceed the revenue generated by the L2". A 98.6% decline in deposits. The yield was a pass-through anyone could get on Ethereum directly MoneyCheck 3 Oct 2026; The Defiant (TVL down 97% from peak)
Arbitrum STIP (L2 programme, Sep 2023) 50M ARB (about $56M) over three months to protocols already live Participating-protocol TVL from $980M on 13 October 2023 to $1.42B on 5 January 2024, up 44.8% Mixed. MUX, the second-largest recipient, lost two thirds of its TVL after the programme ($63.5M to $21.4M). Vertex kept its traders. Gauntlet's LTIPP retro (10 Nov 2024): $689 of TVL per $1 of incentives during, $214 to $243 per $1 counting the period after; 21 of 30 pools kept volume growth. The chain itself held about $2.8B of L2 DeFi TVL in early 2026, because its capital was long-duration, not because of the programme Odaily; Chaos Labs STIP analysis; Gauntlet LTIPP retro 10 Nov 2024; spotedcrypto early 2026 (secondary)
Base (L2, Aug 2023) Distribution: Coinbase's 100M-plus verified users, one-click bridging from a KYC'd account, Coinbase's own products routed through the chain. No token, no points TVL about $2.1B in October 2024 TVL $14.42B on 7 September 2026, the largest L2 by value for most of 2026; about 9.7M user operations a day over the 30 days to 15 September 2026; average fee about $0.016 per transaction, approximate Across blog 2026; shattered.io 15 Sep 2026; spotedcrypto 2026 (fee, secondary)
Monad (L1, Nov 2025) Speed: parallel EVM, 10,000 TPS. 38.5% of supply reserved for ecosystem incentives; Merkl incentives about $75,000 a day (about $27M a year) TVL $150M to $200M on 1 December 2025; about $1.0B in September 2026 with $774M of it stablecoins About 90% of TVL in protocols imported from Ethereum (Uniswap, Curve, Morpho, Upshift); native apps at $1.5M and $5M. MON down 50% while TVL rose. Bridge flows negative on DefiLlama in October 2026 yellow.com 1 Dec 2025; DefiLlama via search 4 Oct 2026; Parameter/MEXC (secondary)
Sei (L1, Aug 2023; EVM 2024; EVM-only mid-2026) Speed: 200,000 TPS target with the Giga upgrade, sub-400 ms finality TVL all-time high over $626M in July 2026 1.3M to 2M daily active addresses against "relatively low" protocol revenue in May 2026, a "monetization gap" the trade press attributes to incentive and airdrop farming (secondary). Tokenomics were rewritten in early 2025 to pay builders instead of stakers iTiger July 2026; bex.co/BingX 2026 (secondary)
Sonic (L1, Sep 2025) Fee Monetization: up to 90% of an app's network fees to the app, 5% burned, the rest to validators. The most generous app share live anywhere Over $2M paid to developers since launch; over 2.6M S earned by builders by February 2026; bridge TVL about $1B at the March 2026 peak Sonic Labs said in February 2026 that the 90% was under evaluation and "should not be treated as permanently guaranteed" Messari FeeM note; cryptowisser; smartliquidity 13 Feb 2025 (secondary)

What the table says, in four lines.

  1. Paying for TVL buys TVL for the length of the payment. Blast paid with points and lost 98.6% of deposits and then the chain. STIP's largest beneficiaries lost most of what they gained. The one durable L2 (Arbitrum) kept capital that had its own reason to stay.
  2. Speed never moved a builder on its own. Monad is the fastest EVM in production and 90% of its value sits in contracts written for Ethereum and copied over. Sei has the addresses and not the revenue.
  3. Distribution is the only thing that worked without paying: Base, with 100 million Coinbase accounts one click away. No new L1 has that.
  4. An app share is a real revenue line only when the chain carries fees worth sharing. Sonic's 90% distributed about $2M in a year across every app on the chain. Canto's 20% is attached to a chain whose whole DeFi TVL is under $2M. The share is a multiplier on fee volume, and fee volume is the thing a new chain does not have.

The litepaper today says "Canto and Blast proved builders come for this" (site/litepaper.html, "What a builder gets for being early"). Blast announced its shutdown on 2 October 2026 and Canto's share pays against a chain with no traffic. That sentence is an overclaim and the proposed replacement is in section 7.

So the question is not "why Igneum rather than Ethereum". It is: what does Igneum have that a builder cannot get on Ethereum or an L2 at any price, and how does a team use it without leaving Ethereum.

2. Igneum's three real differences

2a. The app share: the chain pays apps for traffic

The mechanism, as specified and as implemented. Every transaction pays gas_used x (f_e + tip) + pgas_used x f_p (spec 7.1). Both base fees are burned in full (spec 5.1). The priority fee splits 80% to the block producer and the provers of that block and 20% to apps (spec 5.2). The 20% is attributed per call frame by the execution gas the frame's own opcodes consumed, excluding sub-calls, to the payee registered for the account whose code ran: the callee for CALL and STATICCALL, the code address for DELEGATECALL and CALLCODE, so a library author behind a proxy is paid for the library (design 4.5). Precompile frames and plain transfers have no registration and their share is burned, as is the share of any unregistered contract.

Registration lives in the system contract DeveloperRegistry at 0x0000000000000000000000000000000000000210, in genesis state, slot 0 payee and slot 1 creator (design 10.1, D10). It is populated by rule: on every successful CREATE and CREATE2 the executor writes creator[new] and copies the creator's payee to the new contract, so a factory's children inherit its registration. register(account, payee) is allowed for the account itself or its recorded creator and nobody else. A deployer EOA registers its default payee once with register(self, payee); a contract can change its own payee from its own code. The registry is funded by nothing: it holds no money and takes no fee. The share is credited at execution, every block, as part of the fee flow (design 4.4), and the cost of attribution is an inspector counter per frame.

Measured on the simnet, 3 October 2026 (docs/evidence.md row 22; bench-log "execution layer devnet v3"): a transfer of 21,000 gas at a 1 gwei tip paid 16,800 gwei to the miner (80%) and burned 4,200 gwei (the unregistered 20%); increment(5) at 45,354 gas paid 36,283.2 gwei to the miner and 9,070.8 gwei to the payee the constructor registered, balance delta equal; a deployment through viem's stock deployContract left creatorOf equal to the deployer and payeeOf equal to the constructor argument. The differential harness replayed 79 segments through plain revm with 0 mismatches after adding the Igneum-only flows back.

Parameters, set and open.

Parameter Value Status
App share of the priority fee 20% Designed, implemented on devnet v3 (spec 5.2, 5.9)
Attribution Per call frame by own execution gas, code address Decided (design 4.5, D10)
Registry address 0x…0210, slots payee and creator Implemented (design 10.1)
Who may register The account or its recorded creator Implemented
Factory inheritance Children inherit the creator's payee unless re-registered in the same transaction Implemented
Unregistered share Burned Designed, implemented
Registration format and the re-registration transaction O-5.8, "Open, decision, execution engineer" (spec 06) Open. Proposed below: close it on the devnet form
The registry's upgrade and key policy O-5.4 Open
The default tip a node quotes Not specified; the devnet smoke test used 1 gwei Open. Proposed below
Explorer ranking of apps Must exclude transactions whose sender, coinbase and payee coincide (design 8.4; ledger E3) Designed

The unit economics, worked at devnet fee levels. Devnet constants: B_e = B_p = 30M, both base fees at the 1 gwei floor whenever segments are far below target (bench-log, 3 October 2026: "base fees stayed at the 1 gwei floor throughout"), tip 1 gwei in the smoke test, prototype pgas table at about 0.01 pgas per gas. Take a consumer app call of 100,000 execution gas (a token swap is 110,000 to 150,000 on Uniswap v2, approximate). Prices are the three inputs of docs/analysis/security-budget.md, assumptions and not predictions.

Item Per call At $0.005 At $0.02 At $0.10
User pays: 100,000 x (1 + 1) gwei + 1,000 pgas x 1 gwei 201,000 gwei = 0.000201 IGN $0.0000010 $0.0000040 $0.000020
Burned: both base fees 101,000 gwei
Miner and provers: 80% of the tip 80,000 gwei
App: 20% of the tip 20,000 gwei = 0.00002 IGN $0.0000001 $0.0000004 $0.000002
Daily calls N App share per year at $0.02, 1 gwei tip At $0.10, 1 gwei tip At $0.10, 10 gwei tip
1,000 $0.15 $0.73 $7.30
10,000 $1.46 $7.30 $73
100,000 $14.60 $73 $730
1,000,000 $146 $730 $7,300

A million calls a day is more than any native app on Monad or Sei carries today, and at the high price input with a congested-chain tip it pays $7,300 a year. The honest sentence: the app share is not an income at launch. It is a property of the chain that pays in proportion to IGN price x tip x gas, and the tip on an uncongested chain is whatever wallets quote by default, which can be zero. Any text that calls it "earn the gas you generate" without this table is the Canto pitch.

What the same app's users pay elsewhere, for the same 100,000-gas call. Ethereum at 0.062 gwei (Etherscan gas tracker, 4 October 2026) and about $2,711 per ETH (approximate, September 2026): $0.017; at 1 gwei: $0.27; at 20 gwei: $5.40. Base: average fee about $0.016 per transaction in 2026 (Coin Bureau via spotedcrypto, secondary; the median $0.02 in April 2026). Igneum at the devnet floor and $0.02: $0.000004, which is about 4,000x under Base. The floor is a placeholder constant, not a price: the real base fees adjust toward half of B_e and B_p, and the pgas table's calibration (R1, phase 2) will raise the quoted price of calls heavy in modexp, ecpairing and storage. The design's target is a pgas / gas band of 0.1 to 10 for 95% of the ethereum/tests set (design 4.2), against the prototype's 0.01, so a storage-heavy call should expect its proving charge to rise by one to three orders of magnitude from the devnet figure before mainnet. On any chain the developer pays nothing for its users' gas; "what the app pays" is what its users pay, and the comparison above is theirs.

What a builder actually gets from the app share.

  1. A revenue line that needs no token, no fee switch, no governance vote, no "monetisation" contract and no NFT to claim through (Canto's Turnstile). It is in the fee flow and it is paid to an address every block.
  2. Library revenue. A library called by DELEGATECALL is paid at its code address. On Ethereum a library author is paid by nobody. This is the one part of the share that is new rather than a Canto or Sonic variant.
  3. Protocol-level inheritance. A factory registers once and every pool it deploys pays the same payee; a protocol with a thousand pools has one registration. Canto requires each contract to call Turnstile.
  4. The share comes from the user's tip, never from emission and never from miners' 80%, so no miner has a reason to vote it away (spec 5.5: there is no fund to fight over).
  5. No wash gas. Both base fees are burned in full, so a developer spamming its own contract loses 100% of two base fees and 80% of the tip to recover 20% (ledger E3). The explorer's app ranking excludes self-dealing.

Two proposals, where the parameters are open.

  • O-5.8, registration format. Close it on the devnet form: register(account, payee) callable by the account or its recorded creator; a deployer EOA sets its default once; CREATE inherits. Reasoning: it is implemented, measured (A9's test passes on the simnet) and viem drove it through stock paths; a second format needs a reason and none has appeared.
  • The default tip quote, node policy, not consensus. Specify that eth_maxPriorityFeePerGas and the eth_feeHistory reward percentiles never quote below 1 gwei on an uncongested chain. Reasoning: wallets take the node's quote (MetaMask and Rabby use eth_feeHistory and the priority-fee suggestion, approximate), and a node that quotes 0 under no congestion zeroes the app share for every app on the chain. Ethereum wallets have defaulted to about 1 to 2 gwei of tip regardless of congestion since EIP-1559 (approximate). At 1 gwei the table above holds; at 0 the share is 0. This is a one-line policy in rpc.rs and it should be in design 8.2 next to the gas-price fold. The 20% itself should not move: Sonic's 90% has not retained anything that Canto's 20% did not, and a larger share comes out of the miners' and provers' side, which is the security budget (docs/analysis/security-budget.md section 8 names the priority fee as what miners rely on after year 7 at the low price).

2b. The proving precompile and the miners' GPU market

The mechanism. A system contract Prover at 0x…0200 (design 6): request(program, input, maxPgas, callback) escrows msg.value, which must be at least maxPgas x f_p x 1.5 (the 1.5 is the premium that makes a job worth a card's switch from hashing, Designed, parameter open); a prover runs the registered guest program (any zkVM program for the current ProofSystem version, SP1 at version 1), its job proof is gossiped like a shard proof, a block producer includes a JobRecord, the executor verifies it with the current proof system, stores the result and calls callback.onProof with a 200,000-gas stipend paid from the escrow. The fee splits 90% to the provers who delivered and 10% burned; unused budget is refunded; a job nobody proves in 3,600 chain blocks expires and refunds in full. Jobs are assigned by the same sortition as shards (8 drawn by 30-day weight, a 10-s exclusive window, then open; spec 7.2). The segment proof recursively verifies the job proof, so a light client needs nothing extra and no app has to ship a verifier contract. Full nodes cannot re-run arbitrary programs, so for jobs the proof is the only check (R12: a job output cannot mint IGN or touch system contracts; review with the cryptographer before devnet v2).

Status: Designed. No precompile exists on the devnet (design 10.3 item 5). What exists on 4 October 2026 is the first GPU proof of an Igneum block on an RTX 5090: block 78 (2 transactions, 10 accounts), 626,876 cycles, 14 cycles per EVM gas, core proof 1.4 s, compressed proof 2.7 s, 1.27 MB, verified, state root identical to the node's (bench-log, 4 October 2026). That block is far below one shard, so the times are fixed overhead and not throughput; the throughput number is the phase 2 gate.

The honest comparison with buying proofs today.

Supplier How it is priced A figure, with its label What a buyer must hold
Boundless (RISC Zero), mainnet on Base Reverse auction per request; provers post ZKC collateral; requesters pay in the chain's native token Median lock price about $0.21 per billion cycles across 8 listed provers, 368 orders and 8.4T cycles in the explorer's trailing day; approximate, the explorer prices in MHz and ETH and the dollar figure is from a secondary summary of 4 October 2026 ETH on Base to pay; nothing else
Succinct Prover Network Base fee plus a per-PGU bid in a real-time auction, lowest bid wins, settled in PROVE The quickstart's example request: base fee 0.2 PROVE and a maximum of 2.0 PROVE per billion PGU; at $0.23 per PROVE (2 October 2026) that is $0.046 plus up to $0.46 per billion PGU. These are example parameters, not a market price PROVE, bought on Ethereum mainnet and deposited
Igneum precompile (Designed) maxPgas x f_p x 1.5, f_p an EIP-1559 base fee driven by the unproven backlog, 1 pgas = 1,000 reference-prover cycles At the devnet floor of 1 gwei per pgas: 1 billion cycles = 1,000,000 pgas = 0.0015 IGN with the premium, which is $0.00003 at $0.02. That is a floor at zero demand, not a price: f_p rises with the backlog IGN, which is gas

The floor is 7,000x under Boundless's median and it is meaningless as a quote, because it is the price when the fleet is idle. What it does show is the structure: Igneum's provers are cards that are already on and already paid by the 20% emission pool and the 80% producer share, so a job only has to beat those cards' marginal income for the seconds it occupies them. In the economy model (docs/analysis/economy-2026-10-04.md, baseline scenario, $0.012 per IGN, $0.10 per kWh) a 5090 earns $6.37 per card-day across all modes, so one minute of that card has an opportunity cost of $0.0044 and an electricity cost of $0.0008 at 500 W. The proving throughput that turns a minute into a per-cycle price is unmeasured (ledger P1); the phase 2 benchmark standard (O-7.1: fixed workload, job received to proof accepted, three unrelated operators) is what produces it. Until then the claim is "a supplier whose marginal cost is close to power" (ledger C10 wording), not "the cheapest".

For scale: a 100,000-gas call at 14 cycles per gas is 1.4M cycles, which is $0.0003 on Boundless at the median and 2,100 gwei of proving base fee on the devnet. A billion-cycle job (an Ethereum sync-committee update inside a Helios-class program is of that order, approximate, cycle counts not published in the SP1 Helios docs read) is $0.21 on Boundless.

Where it changes a product, and where it does not yet.

Use case What the precompile gives Honest status
Rollups settling to Igneum A rollup posts its batch as a job; the same miners that secure the settlement layer prove it; the segment proof folds the job proof so the rollup's state root on Igneum is proven and locked in one flow. The customer brief's shape (docs/commercial/prover-customer-brief.md); Taiko is the named first target Designed. Settlement in IGN with the 10% burn waits on the proof bridge (O-5.2). At launch external customers pay on their own chain
On-chain games PREVRANDAO is unbiasable but predictable for the hour (spec 7.1), which is fine for a shuffle revealed later and wrong for a per-block lottery. For adversarial randomness and for any game logic too heavy for the EVM (a chess engine, a physics step), the game commits an input and requests a proof; the callback delivers the result in a later block Designed. Latency is seconds to minutes per job, so it suits turn-based and batch mechanics, not real-time
Batch auctions and solvers A CoW-style batch clears off-chain; the solver proves the clearing (uniform price, every order's limit respected) instead of being trusted or bonded. The contract pays maxPgas x f_p x 1.5 per batch Designed. A batch of a few hundred orders is a small zkVM program; feasible in version 1
Private order flow The chain is public and the protocol adds no privacy (CLAUDE.md: shielded pools rejected 3 October 2026). An app may keep its own inputs inside a proof and publish only the output; that is the app's choice and the proof hides nothing the app does not Permitted by the design; not a protocol feature and must not be described as one
AI inference verification The precompile proves SP1 programs. Running a model inside a zkVM is two orders of magnitude more expensive than the inference itself: a 13B-parameter model takes about 13 minutes of GPU proving per inference in the published zkML systems, and Llama-2-7B takes 388 s with zkLLM (arXiv surveys 2025 to 2026, secondary). Those systems are specialised circuits, not SP1 guests Not a day-one use case. What is feasible in version 1: proving a small model, proving that an output matches a committed model hash and input, and proving the aggregation of many small inferences. The honest line is "verifiable compute", not "verifiable AI"
Ethereum state on Igneum A Helios-class sync-committee proof as a job, so an Igneum contract reads Ethereum finality with no relayer trust (section 3) Designed; the cheapest trust-minimised road from Ethereum into Igneum and the inbound half of the bridge

2c. The miner user base

What exists by construction. The public-testnet gate is 1,000 independent miners for 30 days (site/journey.json, phase 5; "independent" is defined in O-X.1 and is still a Sybil number, ledger X5). Every miner is a funded wallet from the first block it wins and runs the one-click app, which carries a wallet, the node card and an Apps tab (docs/design/phone-app.md; litepaper "Questions builders ask"). Nothing has been measured: the devnet has 9 identities (bench-log, 4 October 2026, devnet v4 cut-over) and the testnet has not opened. "Thousands of holders on day one" is the gate, not a fact.

Why it is still the beachhead. On every chain in section 1 the first users had to be bought. Igneum's first users are the people who mined the coin, hold it in a wallet the project shipped, and have a continuing reason to transact: they are paid every block and they pay power bills every month. That gives a specific set of apps a customer before any consumer app has one.

Miner-shaped apps, concretely.

App What it needs from the chain What exists What is missing
Pools The pool protocol of spec 9: encrypted transport, miner-built templates, the member's own vote key in the header, shares paid by the pool. Payouts can be contracts Spec 9 Designed; nothing implemented The protocol, then a reference pool. A pool whose payout ledger is an on-chain contract (PPLNS settled per block from IgneumInfo data) is the first app a miner would use daily
Rewards-to-contract The block reward is credited to the header's miner address by state transition (design 1.1). That address can be a contract Implemented on devnet v3 for the 80% subsidy; the body miner field is a stand-in (design 10.2) Nothing: a splitter, a vault or a repayment contract as a miner address works once the body field lands. This is a primitive Ethereum does not have for its validators without a withdrawal-credential trick
Hardware finance A card bought on credit mines to a contract that routes the first X IGN a month to the lender and the rest to the owner. Settles on consensus data, no oracle The rewards-to-contract primitive above The per-key block count readable from the EVM, so the contract can verify the card is mining (proposal below)
Hashrate forwards A miner sells its next 30 days of blocks for IGN today; settles against blue blocks per vote key in the window, which is exactly the finality weight W2 getFinalityWeights RPC exists (spec 3.10) Proposal: expose per-key blue-block count and weight in IgneumInfo, so a contract settles a hashrate forward from chain state with no oracle. One read per key per settlement; the data is already maintained for finality
The one-click app's own surfaces The Apps tab, net earnings after an entered tariff, mining and proving income shown apart (ledger X17), the node card Designed (phone-app design) An app registry the tab reads from: the DeveloperRegistry already lists every registered contract and payee, so "registered since block N, payee P, share earned" is a listing the explorer can serve
Proving as a sideline A miner's card answers shard assignments in hybrid mode (the dominant strategy on 24 GB cards in the model, 42 to 54% of cards) and takes precompile jobs Modelled only Phase 2's prover, phase 4's job market

The reason these come first is not that they are glamorous. They have a customer on day one who holds the coin, pays with it already and has a bill to meet, and they exercise the chain's two new primitives (rewards to contracts, weight in the EVM) before any outside team has to trust them.

3. The bridge to Ethereum: the "as well as" mechanism

A team keeps its Ethereum deployment and adds Igneum when state can move between the two without a committee. Two directions, costed separately.

Igneum verified on Ethereum. The segment proof is wrapped once into a curve-based proof (Groth16 or Plonk over bn254, design 5.3; the wrapper's cost on consumer hardware is R4, unmeasured, ledger P3). A Groth16 verification on bn254 through the EVM costs about 194,000 gas measured (NethermindEth frame-verify-gas), or 207,000 plus 7,160 per public input (Orbiter Research). With the wrapped proof's public inputs (segment hash, pre-root, post-root, receipts root, version; packed into a few field elements), one SSTORE of the new root and the calldata, call it 250,000 gas per state root, approximate.

Gas price Per root Every checkpoint (30 s, 2,880 a day) Hourly (24 a day) Daily
0.062 gwei (Etherscan, 4 Oct 2026) $0.04 $121 a day $1.00 a day $0.04 a day
1 gwei $0.68 $1,950 a day $16 a day $0.68 a day
10 gwei $6.80 $19,500 a day $163 a day $6.80 a day
30 gwei $20 $58,500 a day $488 a day $20 a day

ETH at about $2,711 (approximate, September 2026). At today's gas an hourly root costs a dollar a day and a per-checkpoint root costs $44,000 a year; at 2021-era gas the per-checkpoint cadence is unaffordable and hourly is $178,000 a year. The cadence is a bridge operator's choice and a withdrawal waits for the next posted root.

What the execution proof does not prove. A wrapped segment proof says "this post-root follows from these transactions, from genesis". It does not say the segment is on the canonical chain. Canonicity is the lock certificate (spec 3), and verifying it on Ethereum needs the voter list and weights at that checkpoint, which are a function of 30 days of Igneum headers that an Ethereum contract cannot compute. So at launch an Ethereum-side bridge takes the certificate and the voter set from a relayer or a committee it names, and only the execution part is trustless (spec 7.3 item 3; ledger E7, P4, both conceded). Phase two's consensus proof (a zkVM program over the 30-day window and the certificates, folded into the segment proof; design 7, O-10.8) makes one wrapped verification cover finality and execution, and then the bridge needs no relayer and no multisig. Ethereum's BLS12-381 precompiles (EIP-2537, live since Pectra, May 2025, approximate) would let a contract verify the aggregate signature itself once it holds the voter set; the voter set is the part that needs the proof.

Ethereum verified on Igneum. A Helios-class light-client program (SP1 Helios: the Altair sync committee inside SP1, proofs "that a given block was finalized under Ethereum's consensus rules", succinctlabs/sp1-helios) runs as a precompile job. An Igneum contract holds Ethereum's latest finalised header, updated per sync-committee period (27.3 hours) or per finalised epoch (6.4 minutes). The cost is the job's pgas at f_p x 1.5 plus the 200,000-gas callback stipend; the proof is folded into the segment proof, so every Igneum light client inherits Ethereum's header for free. No relayer, no committee, in version 1, because this direction needs only the execution-proof machinery that exists in the design today. This is the asymmetry worth stating plainly: Igneum can read Ethereum trustlessly at launch; Ethereum reads Igneum trustlessly in phase two.

What it takes to build. On Ethereum: a verifier contract for the wrapped proof (generated from the verifying key, standard), a root store, a message-passing contract that checks eth_getProof-style Merkle-Patricia proofs against stored Igneum roots (Igneum's state is a keccak MPT in reth's layout, design 2.1, so Ethereum's existing MPT verifiers apply). On Igneum: the mirror, with the Helios job in place of the verifier. An operator that posts roots at the chosen cadence. Nothing in consensus changes for any of it (spec 7.3). The project ships none of this and calls none of it official (spec 7.3 item 2); it should ship the reference contracts and the operator as open source with the phase two proof.

What it enables. A team deploys once on both chains, keeps its canonical state and liquidity on Ethereum, and moves the compute that is expensive or impossible there to Igneum: the batch auction's clearing proof, the game's engine, the rollup's own proofs, the heavy read of Ethereum state that an L1 contract cannot afford to verify. Results come back as proofs Ethereum verifies for 250,000 gas. That is the "as well as": Ethereum stays the settlement and the liquidity, Igneum is the proven compute and the second market. An L2 can offer cheap execution; it cannot offer a prover population paid by emission, and its proofs still come from a prover market it rents.

4. The cold start, and the sequence

Stated plainly. On 4 October 2026 Igneum has no precompile, no job market, no pool protocol, no explorer, no public RPC, no stablecoin, no bridge, no coin and nine devnet identities. Every chain in section 1 had more than that at launch and most of them still lost their builders. Nothing in sections 2 and 3 is a reason for a consumer-app founder to deploy before the chain has a public track record of the three mechanisms.

The sequence, keyed to the roadmap (site/journey.json).

Order Who builds When the chain can carry it Why this order
1. Miner-facing apps The team and the first pool operators: the pool protocol and a reference pool, rewards-to-contract vaults, the Apps tab, hashrate forwards once IgneumInfo carries weight Devnet now for contracts; pools at the phase 4 devnet; real customers at public testnet (Aug to Oct 2027) The customers exist by construction and they exercise the new primitives first
2. Verifiable-compute apps The first rollup customer (Taiko named; the brief lists ten), a batch-auction solver, a Helios job, one reference app that uses the precompile end to end Phase 4 (Apr to Jul 2027): the job market on the devnet, gate "one rollup signs for testnet" These are the only apps for which Igneum is the cheapest supplier of something they already buy. The external review's advice stands: one excellent proof-request workflow and one reference application before any broad ecosystem (docs/review/external-2026-10-03.md, point 7)
3. Consumer apps Outside teams, on their own judgement After mainnet (Nov 2027) and after a published record: app share paid for N blocks to M registered payees with the self-dealing filter applied, job prices and delivery times on the evidence page, a bridge operated by a named party The app share has to show a number before it is a pitch. Section 1 says a consumer app that comes earlier comes for a payment, and leaves with it

What a developer fund can and cannot buy. The ask names "the foundation's developer fund (fee-funded)". There is none. Spec 5.5, decided 3 October 2026: "There is no development fund and no protocol fee to any team, foundation or fund." The 5% of tips and 5% of job fees that earlier drafts routed to a fund were removed. What exists: the litepaper's "Launch grants. Paid from the founders' own mined coins, never from emission, to the first apps that bring users", which docs/plans/funding.md does not budget and which the round-3 review flagged as the founders funding user acquisition (docs/review/round-3-2026-10-03.md, line 344); and the 60% parameter-signalling path by which miners could add a grant mechanism later (spec 5.5, 5.8). Both are unfunded today; the funding plan is a placeholder and its unfunded half is audits, not grants.

What the evidence of section 1 says a grant buys, whoever pays it: a deployment and a TVL number for the duration of the payment (STIP: 44.8% during; MUX lost two thirds after; Gauntlet: $689 of TVL per dollar during, $214 to $243 after), and a line in the ledger about founders paying for users. It does not buy retention. Base retained because of distribution, Arbitrum retained the capital that was long-duration anyway. The recommendation, which is a decision for the project lead and counsel (ledger L1, L2): spend founder coins on the three things that produce a track record (the reference apps of rows 1 and 2, the bridge contracts, the audits in funding.md that are unfunded), and never on a TVL programme. If "launch grants" stay in the litepaper they should name what they pay for (an audit, a port, an integration) and never a user count.

5. The developer-experience checklist

What a builder expects on day one, what Igneum has, and the order to build the rest. "Has" means implemented on the devnet v3 execution layer unless stated (design 10).

Item Expected Igneum has Lacks Order
EVM Cancun, same bytecode Cancun opcodes, precompiles 0x01 to 0x09, revm 43; chain ids 4461 / 4462 / 4463; viem 2.57 drove deploy, write, read and fee estimation through stock paths EIP-7702, 0x0a, blobs (by design); the documented differences table of spec 7.1 must be in the developer docs Docs: 1
RPC Full eth_*, debug_*, trace_*, subscriptions 25 eth_* methods, igneum_getTransactionStatus, igneum_getSegment, igneum_getBudgets, igneum_estimateGas (both dimensions); HTTP JSON-RPC 2.0 with batches, port 26790 eth_getProof, eth_subscribe, debug_traceTransaction, trace_block, eth_getUncle*, IgneumInfo (design 10.3 item 7); pending, safe, finalized all resolve to the executed tip 2 (debug and subscribe are what Blockscout and Foundry's debugger need)
RPC providers A public endpoint, then third parties None public. The devnet is the team's three nodes and a seed A public devnet RPC with a rate limit; chain-id registration on ethereum-lists/chains before the public testnet (design 8.1) 3
Tooling templates Hardhat and Foundry work Designed: templates "ship with the devnet" with the three things to tell a developer (design 8.3) The templates themselves; a vm.warp note (past timestamps rejected) 1
Explorer Blockscout with verified contracts site/live.html shows the live DAG and identities The Blockscout fork: DAG panel, four-state chip, skipped tab, two base fees, app leaderboard with the self-dealing filter (design 8.4; R10, A8) 4
Indexers Subgraph or equivalent Nothing Standard eth_getLogs and contiguous block numbers mean The Graph's node should index unchanged (design 3's reason for selected-chain height); untested 5
Wallets MetaMask, Rabby, hardware The folded gas quote is designed so unmodified wallets work; A7 (MetaMask sends a transfer and a call) is a devnet v1 criterion, not yet run R11: test MetaMask, Rabby and Frame against the devnet; the chain-id listing 3
Bridges A canonical bridge, a stablecoin None, by decision (spec 7.3). The proof bridge is phase two Reference bridge contracts and an operator (section 3), labelled unofficial After phase two
Audits Audited execution layer and precompile None. The execution and proving-integration audit is unfunded (funding.md: USD 80,000 to 150,000, "mainnet does not ship with an unaudited execution layer") The audit Before mainnet, by rule
Docs A docs site: quickstart, differences, gas, the precompile, the registry The spec and design documents in the repository, private A public docs site built from spec 7 and design 3, 4, 6, 8; the public repo decision (G11) 1, with the public repo
Testnet faucet Free test coins None. The devnet has no faucet; the public testnet opens Aug 2027 A faucet on the public devnet RPC 3
Status semantics finalized means finalised The four-state rule (included, executed, proven, finalised; design 2.4) and the conformance set O-7.2 The RPC tags still resolve to the executed tip on devnet v3 2

Order in one line: docs and templates first because they cost a day and nothing else is usable without them; the missing RPC methods second because the explorer and the debugger depend on them; a public endpoint, chain-id listing, wallet tests and faucet third; the explorer fourth; indexers fifth; the bridge after phase two; the audit before mainnet by rule.

6. Ten reasons a sharp founder says no

Each answered or conceded. The conceded ones are ledger section 9, entries D1 to D6.

# The objection Answer or concession
1 "You have no users. The miners are a gate, not a fact, and 'independent' is a Sybil number." Conceded (D1). Nine devnet identities today; 1,000 is the testnet gate and X5 says the definition is pending. The beachhead argument of 2c is a plan, and the plan is honest about that
2 "Your app share pays nothing. Run your own table: a million calls a day is $146 a year at your base price." Conceded (D2). The share is a property, not an income, and section 2a says so with the table. The litepaper's "earn the gas they generate" is rewritten in section 7
3 "Proof of work in 2027. My investors and the exchanges I need read 'GPU-mined' as 2021." Partly conceded (D3). The chain's energy buys proofs as well as ordering (litepaper "Questions builders ask"); that is an argument, and the perception cost is real and unmeasured. Nothing in this document changes it
4 "No stablecoin and no bridge at genesis. There is no DeFi without a dollar." Conceded by decision (ledger E7, closed; D4 cross-references it). The alternative was a multisig bridge the design refuses. Native USDC "requested from Circle" is a request, not a commitment, and the round-3 review already asked for that sentence to go
5 "'EVM unchanged' is false: block.number is chain height on a DAG, timestamps can hold still, PREVRANDAO is predictable for an hour, my modexp costs more, and my transaction can be skipped and re-included without my knowing." Answered by spec 7.1's table and the four-state rule; "unchanged" is already conceded (ledger P5) and the public text must say "documented differences"
6 "No eth_subscribe, no debug_trace, no eth_getProof, no explorer, no public RPC, no faucet. I cannot even debug a revert." Conceded (D5). Section 5 lists each with an order; the first three are design 10.3 item 7 and come before any outside team is invited
7 "A soundness bug in SP1 forges a job result into my contract, and for jobs there is no native veto." Partly conceded (D6). Segments carry the native-execution veto (ledger P7); jobs do not, by necessity (design 6: "for jobs the proof is the only check"). The containment is R12: a job output cannot mint IGN or touch system contracts, and jobs are gated by proof-system version with a three-month overlap. An app that acts irreversibly on a job output should keep its own fallback, as the customer brief tells rollups
8 "Finality pauses when a third of weight goes quiet. I cannot show my users 'finality not active' on a lending market." Answered by design and already conceded in the ledger (F9, F18): the chain runs on proof of work during a pause, the node reports it, and the four-state rule forbids any surface from showing "finalised" meanwhile. A lending market acts on executed state as it does on every chain; only irreversible actions (bridge withdrawals, exchange credits) wait for a lock, and they wait longer during a pause
9 "Executed state can be reorged for an hour (merge depth 3,600 s). My game paid out on executed state." Answered: the observed devnet reorg depth is 1 to 3 blocks (design 10.2) and the lock lands in about two minutes (spec 3.2 C1); the rule for apps is the one Ethereum has, act on executed state for the reversible and wait for the lock for the irreversible. The hour is the bound, not the typical case, and R6 measures the distribution
10 "Why not an L2 on Ethereum with a prover market? I get Ethereum's security and liquidity for free." Answered in part: an L2 cannot have a prover population paid by emission, miner-weighted finality that no stake can buy, or a fair-launch holder base; its proofs come from a market it rents (Boundless, Succinct) at the prices in 2b. Conceded in part: an L2 gets Ethereum's liquidity and a trustless bridge on day one and Igneum gets neither before phase two. That is why section 3 is "as well as" and not "instead of"

7. The public text, proposed and not applied

Replaces, in site/litepaper.html, the sub-heading "What a builder gets for being early" and its five bullets inside <section id="building">, and the answer to "What do I get for being early?" in <section id="builders-ask">. The homepage Build card's sentence is replaced too. Copy law applied: no em dashes, no two-beat antithesis, no aphorisms, short sentences, numbers in tables where they belong. Word count of the litepaper section: 297.

Litepaper: "Why build here" (proposed diff)

--- a/site/litepaper.html
+++ b/site/litepaper.html
@@ <section id="building"> @@
-        <h3>What a builder gets for being early</h3>
-        <ul>
-          <li><strong>Apps earn the gas they generate.</strong> 20% of every transaction's priority fee goes to the contracts whose code ran, by gas consumed inside each, paid every block to the developer address registered at deployment. Canto and Blast proved builders come for this. On Igneum it comes out of fees, never out of miner emission.</li>
-          <li><strong>Stablecoins.</strong> None are bridged at genesis. No bridge is official, anyone may run one at their own risk, and the proof bridge that needs no multisig arrives with the consensus proof in phase two. Native USDC is requested from Circle during public testnet. Igneum issues no stablecoin of its own.</li>
-          <li><strong>Liquidity from the people who are there.</strong> The DEX is seeded by the founders' own mined coins and by miners, and every miner is a funded wallet from day one.</li>
-          <li><strong>Launch grants.</strong> Paid from the founders' own mined coins, never from emission, to the first apps that bring users.</li>
-          <li><strong>A minute of proof lag costs you nothing.</strong> Execution is immediate, the block is locked by miners in about two minutes, and the proof is a guarantee on top. A bridge built on Igneum can release a withdrawal after the lock, about two minutes, against seven days on an optimistic rollup.</li>
-        </ul>
+        <h3>Why build here</h3>
+        <p>Not for speed. Fast EVM chains filled with copied Ethereum contracts and emptied when incentives stopped. Three things no L2 can offer. Keep your Ethereum deployment.</p>
+        <ol>
+          <li><strong>Proofs at the cost of power.</strong> A contract requests a proof of any computation and the miners produce it. Their cards already run and are paid by emission, so a job only has to beat a few seconds of lottery income. Verification is folded into the chain's own proof; you ship no verifier. The price is a base fee that rises with the backlog, published at the phase 4 job market.</li>
+          <li><strong>Users who were not paid to arrive.</strong> Every miner is a funded wallet. Pools, payout contracts, hardware finance and hashrate forwards have customers before any consumer app does. Block rewards can pay straight to a contract.</li>
+          <li><strong>A share of fees, with the number stated.</strong> 20% of every priority fee goes to the contracts whose code ran, per call frame, to the payee registered at deployment. Libraries are paid at their code address. Factories pass their registration to what they deploy. At launch fee levels this is a property, not an income: a million calls a day at a 1 gwei tip pays about 7,300 IGN a year. It grows with traffic and nothing else.</li>
+        </ol>
+        <p>Ethereum stays your settlement. Move heavy compute to Igneum and return the result as a proof Ethereum verifies for about 250,000 gas. Igneum reads Ethereum's finality trustlessly from launch. Ethereum reads Igneum trustlessly in phase two. Until then, trust the bridge's operator.</p>
+        <p>No stablecoin and no official bridge at genesis. Grants come from founders' mined coins, for ports, audits and integrations, never for a user count. Execution is immediate, the miner lock lands in about two minutes; a withdrawal waits for the lock.</p>
@@ <section id="builders-ask"> @@
-        <h3>What do I get for being early?</h3>
-        <p>20% of the priority fee on every transaction that runs your code, paid to you every block. Launch grants from the founders' mined coins. A place in the wallet's Apps tab and the explorer from day one. And the only user base a new chain has ever had that did not have to be paid to arrive.</p>
+        <h3>What do I get for being early?</h3>
+        <p>20% of the priority fee on every transaction that runs your code, paid to you every block, which at launch fee levels is small and stated as such above. A place in the wallet's Apps tab and the explorer from day one. First access to the proving precompile and the job market. And a user base that was not paid to arrive: the miners.</p>

The sentence "Canto and Blast proved builders come for this" is removed on the evidence of section 1 (Blast shut down on 2 October 2026; Canto's share pays against a chain with under $2M of DeFi TVL). The 7,300 IGN figure is 1,000,000 calls x 365 days x 0.00002 IGN per call, from the table in 2a.

Homepage: three sentences for the Build card (proposed diff)

--- a/site/index.html
+++ b/site/index.html
@@ <div class="job reveal"> Build @@
-        <p>Ethereum bytecode unchanged, with 20% of priority fees paid back.</p>
+        <p>Ethereum bytecode, with the differences documented. Proofs of any computation from the miners' cards, verified by the chain itself. 20% of priority fees to the contracts that ran, stated at the fee levels that exist.</p>

8. Hostile review of this document, three roles, folded in

Ethereum core developer. Findings: (1) "Your app share and precompile numbers at the devnet floor are placeholder constants and you present them next to real market prices." Folded: every floor figure is labelled a floor at zero demand and the Boundless comparison is stated as structure, not price (2b). (2) "The execution proof on Ethereum proves execution, not canonicity; your bridge section implied otherwise." Folded: section 3 separates the two and says the launch bridge trusts a relayer for the certificate. (3) "eth_getProof is missing and your state is in memory and recomputed per segment; eth_getProof is what every bridge and light client reads." Folded: section 5 lists it at order 2, and section 3 notes the keccak MPT layout is what makes Ethereum's verifiers reusable once it exists. (4) "DELEGATECALL attribution to the code address means a proxy's upgrade changes who is paid; say so." Folded into 2a item 2: the code address that ran is paid; an upgrade moves the payee to the new implementation's registration, which is the intended rule (design 4.5's rejected alternative). (5) "EIP-2537 is on mainnet; your bridge could verify the BLS certificate directly if it knew the voter set." Folded: section 3 says exactly that, and that the voter set is the part needing the proof.

Solana-style performance maximalist. Findings: (1) "One block a second and a 10-s to 60-s proof lag; a game's job comes back in a later block. You cannot host anything real-time." Folded: the use-case table says turn-based and batch mechanics only, and the latency is stated. (2) "Your proving fleet is over-provisioned at launch traffic because there is no traffic; at 100 shards a block the model backs up unless the window is 20 s." Folded: the economy analysis is cited with its traffic sensitivity and the fleet-capacity bound; the precompile section does not claim capacity it has not modelled. (3) "A million calls a day is 11.6 a second; your B_e of 30M gas a block at one block a second is about 300 calls a second, so that is not even a stress test." Accepted and used: the table's largest row is small by design and the point stands that the share is small even then. (4) "Verifiable AI is a slogan; a 7B model is six minutes of GPU proving in the best published system and that is not SP1." Folded: the use-case table says "verifiable compute, not verifiable AI", with the figures and their labels.

Consumer-app founder burned by an L2 incentive programme. Findings: (1) "Your litepaper says 'launch grants to the first apps that bring users'. That is the programme that burned me." Folded: section 4 recommends grants buy ports, audits and integrations and never a user count, and the proposed litepaper text says so; the decision is the project lead's. (2) "Show me the number before the slogan." Folded: the table in 2a and the "property, not an income" sentence, in the public text too. (3) "Who do I call when a transaction is 'included' and never executes?" Folded: the four-state rule and igneum_getTransactionStatus are in sections 5 and 6, and the skip-and-re-include behaviour is in objection 5. (4) "I need a stablecoin, a bridge and a fiat on-ramp or my users cannot exist. You have none and you say phase two." Conceded (D4) and sequenced: consumer apps are row 3 of section 4, after mainnet and a track record. (5) "The miners are your users? Miners sell. They are the most mercenary users of all." Partly conceded in D1: the claim is that they are funded and present, not loyal; the apps that work for them are the ones that help them earn, pay and finance, which is why they are the beachhead and not the market.

9. What this document asks for

Ask Owner Where
Close O-5.8 on the devnet registration form Execution engineer Spec 5.2, 06
Specify the 1 gwei tip-quote floor as node policy Execution engineer Design 8.2
Expose per-key blue-block count and weight in IgneumInfo Execution engineer, consensus engineer Design 3, spec 7.1
Replace the litepaper's "Canto and Blast" bullet and the homepage Build sentence with section 7's text the project lead's go, then the site owner site/litepaper.html, site/index.html
Re-scope "launch grants" to ports, audits and integrations, or remove the line the project lead, counsel (L1, L2) Litepaper
Ledger section 9, entries D1 to D6 This document docs/fud-ledger.md
The developer-experience order of section 5 Execution engineer Design 8, 10.3