24 KiB
Igneum evidence: every public claim, with its status
3 October 2026. One row per claim the homepage (site/index.html) and the litepaper (site/litepaper.html) make. Every number here is copied from docs/bench-log.md, which names the machine, the date and the command; nothing is restated from memory. Where a bench-log figure is approximate, this table says so.
The five labels
| Label | Meaning |
|---|---|
| designed | A decision in the design document or the specification. No code carries it, or the code is a stub |
| implemented | Code exists in this repository with test vectors, and the vectors pass. Not run as a measurement of the claim |
| tested by the team | The claim was measured or exercised by the project's own people and agents on a named machine, and the result is in the bench log |
| reproduced externally | Somebody outside the project ran the published command on their own hardware and got the published result |
| reviewed independently | Somebody outside the project, paid or not, read the code or the rule and published their finding |
Three rules for reading the table:
- Nothing on this chain has been reproduced externally or reviewed independently. Every row's last column says "none yet". The repository is private until January 2027 (
site/journey.json), so the first two labels are the ceiling today. - A status applies to the exact version in the row. An audit of one version never covers a newer one; when the version changes, the status falls back to "tested by the team" until the new version is reproduced or reviewed again.
- "Tested by the team" on one machine is one machine. The rows say which. Discrete AMD, Intel and a 2019-class CPU core have not run anything.
Versions in the table: igneum-pow is the Rust crate at igneum-pow/Cargo.toml version 0.1.0. "Repo" commits are this repository's. "Fork" commits are vendor/igneum-node and its worktrees (-r3, -diff, -exec, -harness), which are not in this repository's history; the row names the fork commit by its message as the bench log does. The spec is docs/spec/ version 0.1.
The table
| # | Claim | Where it is made | Status | Version or commit | Reproducible test | Result, date, machine | Independent verification |
|---|---|---|---|---|---|---|---|
| 1 | A new mining program every hour, compiled by the miner, with no human in the loop | Homepage hero and "This hour's mining program"; litepaper Mining | tested by the team | igneum-pow 0.1.0; repo 9812466; fork "PoW: header-bound lottery engine, real-hash miner modes, genesis bits 0x1e400000" |
igneum-miner mine --engine igneum-pow against a 3-node igneumd --devnet, with proto-metal/igneum-bench --serve as the GPU worker; bench-log "first devnet blocks on the real lottery hash" |
Epoch change crossed live at DAA 3,600: new seed, a 128-load program compiled by the Metal worker in 129 ms, 0 rejected blocks across the change. 3 October 2026, Apple M5 Max. The epoch seed on the devnet is the epoch block hash; the VDF of row 2 is not wired in yet | none yet |
| 2 | The program seed passes through a 10-minute verifiable delay from a certified checkpoint, so nobody can grind the seed | Litepaper Mining, vs RandomX ("Closed by a verifiable delay") | implemented | repo 792776e; proto-vdf/ |
proto-vdf full 10-minute runs and the tamper cases in proto-vdf/README.md; bench-log "proto-vdf" |
Class group 1024-bit: 163,000 squarings per second, 10-min eval 585.4 s, prove 9.1 s on 12 threads, verify 4.47 ms, 516-byte proof; wrong checkpoint, flipped seed bit and T+1 all rejected; grinding model gains 0 blocks per epoch with the delay against +3.62 at a 30% advantage without it. 3 October 2026, Apple M5 Max, one core. Prototype only: not in the node, not reviewed against chiavdf (O-4.1) | none yet |
| 3 | The dataset is memory-hard: computing an item costs more than loading it | Litepaper Mining and vs RandomX; homepage vs RandomX ("Memory 2 GB, growing") | tested by the team | repo 58a5a63; igneum-pow 0.1.0 (memhard.rs); proto-metal/MEMHARD.md |
proto-metal/igneum-bench --inline-dataset against the honest run at 1 GiB and 256 MiB; bench-log "memory-hard dataset" |
Honest 45.2 Mhash/s, inline (never reads the dataset) 9.49 Mhash/s, ratio 0.21, at 1 GiB; 0.10 at 256 MiB. 3 October 2026, Apple M5 Max. Apple only: the shortcut ratio has not run on NVIDIA or AMD (O-1.5). Review round 3 priced a 256 MiB on-die cache chip at about 2.4x, approximate, which the measurement does not answer (ledger M16) | none yet |
| 4 | The same program produces identical hashes on three GPU vendors, cache and dataset included | Litepaper vs RandomX ("Bit-exact on Apple and NVIDIA, measured"), For miners; homepage | tested by the team | repo f2e903e, 0f1fdaf; pack proto-cuda/packs/igneum-genesis-mh; igneum-pow 0.1.0 |
The 96 test vectors of the pack through proto-metal/igneum-bench, proto-cuda/host.cu, proto-opencl/host.c; batch fingerprint at --batch-log2 24; bench-log entries "RTX 5090, memory-hard dataset", "AMD gfx1036", "RTX 5090 through NVIDIA OpenCL" |
96/96 on Apple Metal (M5 Max), NVIDIA CUDA and NVIDIA OpenCL (RTX 5090, Windows), AMD OpenCL (Ryzen 7 9800X3D integrated gfx1036, 1 compute unit), Apple OpenCL, pocl and two CPU references; batch fingerprint 98af644e993239e2 over 16.7 million nonces identical on the AMD chip and the 5090. 3 October 2026. The AMD device is an integrated chip; no discrete AMD card and no Intel card has run anything (O-1.15) |
none yet |
| 5 | A CPU verifies one hash in under 10 ms by simulating one warp | Litepaper Mining ("about ten milliseconds"), vs RandomX; roadmap gate 2 | tested by the team | repo 75cac18; igneum-pow 0.1.0 (verify.rs) |
cargo test and the crate bench in igneum-pow/; bench-log "igneum-pow: Rust crate bit-exact with proto-metal" |
0.411 to 0.579 ms per 32-lane warp steady, 0.41 to 0.87 ms cold, average of 20, 1 GiB dataset, cache held, one M5 Max performance core; the Swift verifier 0.63 to 1.2 ms. Gate margin about 17x on this core. 3 October 2026. Not measured on a 2019-class laptop core (O-1.14) | none yet |
| 6 | The hash is bound to the header: one nonce serves one header, and a wrong nonce is rejected | Spec 1.6; litepaper Mining (implied by "checks a hash") | tested by the team | repo 33f7b33, 9812466; igneum-pow 0.1.0 (bind.rs, 8 bound vectors, 29 crate tests) |
igneum-miner bad-nonce against a devnet node; igneum-pow hash-bound for the 96-nonce job across the 2^32 lane boundary; bench-log "first devnet blocks on the real lottery hash" |
833 blocks accepted by igneum-lottery-v1-bound on 3 nodes, 0 rejections; bad-nonce gave Reject(BlockInvalid); Metal, OpenCL and CUDA (emulated) workers bit-exact with the crate on the lane-boundary job. 3 October 2026, Apple M5 Max |
none yet |
| 7 | The devnet runs at one block a second | Homepage stats ("1 / s"); litepaper Speed; roadmap phase 3 | tested by the team | repo 9812466, e9328c6; fork worktree vendor/igneum-node-diff branch difficulty |
3-node CPU devnet, igneum-miner mine --engine igneum-pow, 660 s; the dual-lane rule's 3-node test network (ports 26800 to 26821); bench-log "first devnet blocks" and "difficulty controller" |
CPU devnet: 1.29 blocks/s over 641 s, 1.03 blocks/s over blocks 610 to 816 after the first retarget, sink identical on 3 nodes at 61 of 64 samples. Kaspa's sampled rule on the overnight devnet did not hold the rate across a hashrate step (5.44 blocks/s for five minutes, 4.7x the schedule for eight minutes). The Igneum dual-lane rule's test network reached 1 block/s within 10% after 132 s, worst gap 7.3 s. 3 October 2026, Apple M5 Max. The phase 3 gate also asks for proofs under 60 s behind the tip; no proof exists (row 15) | none yet |
| 8 | Blocks are mined by GPUs on Apple and NVIDIA | Homepage live strip; journey phase 3 ("GPU miners on three vendors") | tested by the team | repo 9812466, e9328c6; fork as row 1 |
Metal worker proto-metal/igneum-bench --serve driven by igneum-miner --worker, 300 s; the overnight devnet record sim/difficulty/devnet-2026-10-03.csv; bench-log "first devnet blocks" and "difficulty controller" |
Metal: 506 jobs, 5,636 blocks found and accepted, 0 rejected, 0 CPU/GPU mismatches, 28.2 MH/s wall. NVIDIA: the overnight devnet record shows the PC's RTX 5090 mining at 116 MH/s estimated from the blocks, and the finality follower counted eight RTX 5090 identities at 862 to 936 blocks each. 3 October 2026, Apple M5 Max and the Windows PC | none yet |
| 9 | Blocks are mined by a GPU on AMD | Journey phase 3 ("three vendors") | implemented | repo 0f1fdaf; bound kernel kernel_bound.cl in the pack |
proto-opencl/host.c --serve on an AMD device against a devnet node |
The bound OpenCL kernel is bit-exact with the crate on Apple OpenCL and the memory-hard pack passes 96/96 on AMD gfx1036, but no block count mined by an AMD device is recorded in the bench log. Until one is, the three-vendor mining claim is two vendors mined plus one vendor verified | none yet |
| 10 | Checkpoints lock every 30 s of chain at two thirds of all 30-day weight (raised from 56.7% of total on 4 October 2026), and the floor stops conflicting locks in partitions and eclipses | Litepaper Finality, "What Igneum does not claim"; homepage "locked every 30 seconds" | tested by the team | repo bbb264a (simulation), 60b1412 (fork run); fork "Finality: BLS12-381 vote keys ..." through "Miner: BLS identity ..."; spec 3.10 |
sim/finality_v2.py (results in sim/results_v2.md); the 4-miner test network igneum-devnet-7 with getFinalityCheckpoints on three nodes; bench-log "finality rule V2" and "igneum-node devnet v2" |
Simulation: 0 conflicting locks in every honest partition and eclipse scenario with the floor; without it both sides of a 50/50 split lock after 60 min. Test network: 72 of 72 determined checkpoints locked on all three nodes, lock latency median 0.80 s, p90 1.08 s, 0 conflicting certificates; an equivocating key stripped at index 43 and excluded; with one voter left (39.6% of total) 0 locks for 749 s, then the heal locked 13 checkpoints within 30 s. 3 October 2026, Apple M5 Max, 53 minutes. Not on the live devnet (its miners do not vote yet); the simulation has no DAG; one unexplained stall of all three nodes in the first run, not reproduced | none yet |
| 11 | Hashrate that arrived today has almost no vote: ten days of the whole network's hashrate to reach a third of the weight, twenty for two thirds; 51% never reaches two thirds while honest miners stay | Litepaper Finality; homepage firsts | tested by the team | repo bbb264a; sim/finality_v2.py |
Scenario B of sim/finality_v2.py, seeds 7 and 11 |
share(t) = (t/30) x a/(1+a) holds to 0.04 points; a renter equal to the whole honest network (a = 1) crosses 1/3 on day 20 and never reaches 2/3; a = 9 crosses 1/3 on day 11.1 and 2/3 on day 22.2. The ten-day figure is a = infinity, honest miners gone. 3 October 2026, Apple M5 Max. A model with 1,000 Pareto keys and no DAG; the harness scenarios against the real node (1b, 3b, 4b) are stubs | none yet |
| 12 | The difficulty rule recovers from a hashrate step within about a minute, where Kaspa's sampled rule never settles | Spec 2.3; litepaper Speed (implied); bench page | tested by the team | repo e9328c6; fork worktree vendor/igneum-node-diff branch difficulty; sim/difficulty/sim.py |
sim/difficulty/sim.py on nine profiles plus the devnet record; the 3-node test network with "difficulty_rule" in the override file; cargo test -p kaspa-consensus --lib difficulty (9 pass); bench-log "difficulty controller" |
Simulator, settled seconds: x50 step 62 (Kaspa 1,542), /50 step 657 (Kaspa 12,296), the devnet's 75x step 79 (Kaspa never). Test network: within 10% of 1 block/s after 132 s warm-up, 214 s on a join, 85 s on a leave. 3 October 2026, Apple M5 Max under load 50 to 98. Monero and LWMA baselines reproduced from memory, approximate; no DAG in the simulator; harness scenarios 2b and 7b are stubs | none yet |
| 13 | Every node executes the ordered transactions natively and reaches the same state root | Litepaper Proving ("Every node executes ... natively"), Building ("runs on Igneum unchanged") | tested by the team | repo f5f8c80; fork worktree vendor/igneum-node-exec branch execution-layer; revm 43.0.3 |
node tools/evm-smoke/smoke.mjs against a 3-node igneumd --simnet; igneum-exec-diff seq.json; bench-log "execution layer devnet v3" |
87 of 87 viem checks; state roots identical on 3 nodes at chain blocks 0, 56, 74 and 78; 57 executed transactions and 19 skipped copies agree with plain revm, 0 mismatches; balances match receipts to the wei. 3 October 2026, Apple M5 Max. Simnet skips proof of work, the prover is a stub, state is rebuilt from genesis at start, no EVM transaction relay between nodes | none yet |
| 14 | Ethereum bytecode runs unchanged, with the documented differences of spec 7.1 | Homepage Build card; litepaper Building | tested by the team | as row 13 | tools/evm-smoke/smoke.mjs: deploy via viem, increment, hashLoop, eth_estimateGas, eth_getLogs |
Deployment, calls, reverts, logs and gas estimates behave as viem expects; chain id 4463; the prototype pgas table gives 0.0095 to 0.028 pgas per gas, below the design's band before calibration. 3 October 2026, Apple M5 Max. The Prover precompile, proof records and the shard planner are not implemented |
none yet |
| 15 | Every block is proven, with the proof landing within about a minute at launch | Homepage stats ("~60 s to a proof"); litepaper Proving; roadmap phase 3 gate | designed | spec 7.2; docs/design/execution-layer.md section 5 |
None exists. The phase 2 benchmark standard is docs/benchmarks/proving-e2e.md |
No SP1 shard has been proven on any card in this repository (ledger P1, P3). The devnet prover is a stub that signs claims. The 60-second figure is a design target | none yet |
| 16 | A 12 GB card proves one shard in about 20 s | Litepaper Proving ("The proving budget"); roadmap gate 2 | designed | spec 5.1 (Target) | Replaced as a gate by the end-to-end standard in docs/benchmarks/proving-e2e.md: fixed workloads, job-to-accepted-proof latency, no growing backlog |
Unmeasured. A per-shard time can be met by shrinking the shard, so the project no longer uses it as a pass mark | none yet |
| 17 | The chip resistance target: a chip gains under 2x over a GPU | Litepaper Mining, "What Igneum does not claim"; homepage "no chip can be built for it" | designed | spec 0.2 (Target); O-1.17 | Public benchmark with a leaderboard by card model and a standing bounty, January 2027 (O-1.17); the on-die-SRAM test on the RTX 5090 (R3.5) | A target, not a measurement. Review round 3 priced a recompute chip with the 256 MiB cache on die at about 2.4x, approximate, before the usual chip-versus-GPU integer gain; the design answer (cache larger than any die) is open (spec 1.16) | none yet |
| 18 | The chip resistance measurements: the program is random-access bound, not bandwidth bound, and sits beyond a card's on-chip cache | Litepaper Mining ("bound by memory bandwidth", to be corrected), vs RandomX "Measured so far" | tested by the team | repo aba248d, f2a1a64, 4b95c5e |
RTX 5090 dataset sweep 4 MiB to 1 GiB with proto-cuda/host.cu; bench-log "RTX 5090 first run" and "dataset sweep" |
At 1 GiB: 228.1 Mhash/s, 23.7 G random loads/s, 94.9 GB/s useful against a 1,638 GB/s dataset fill; inside the 96 MiB L2 (4 and 64 MiB) 1,340 to 1,353 Mhash/s, about 5.8x faster; 104 against 128 loads per hash gives 228 against 185 Mhash/s, proportional. 3 October 2026, RTX 5090, Windows, CUDA 12.8. Prototype dataset 1 GiB against 2 GB at genesis; a pure random-read microbenchmark (R3 chip designer, attack 2) has not run | none yet |
| 19 | The lottery hash is sound as a hash: uniform output, deterministic, no out-of-bounds read, fuzzed | Litepaper vs RandomX ("Every number above is measured and logged") | tested by the team | repo c52307e, 58a5a63; proto-metal/TESTS.md |
proto-metal/igneum-bench --fuzz --edge --stats --determinism --memcheck; bench-log "hardening tests" and the re-run on the memory-hard dataset |
10,200 random programs, 1,305,600 hashes, 0 mismatches; 14 of 14 edge cases; bit frequency within 2.90 sigma, avalanche mean 31.99 to 32.04 of 32; deterministic fingerprint across 5 runs; every dataset read masked. 3 October 2026, Apple M5 Max. Statistics are not a security proof; the weak-program census (O-1.3) and the seed derivation review (O-1.4) are open; the fuzz set has run on Metal and the CPU only | none yet |
| 20 | No premine, no pre-sale, no allocation: every coin is minted by the schedule and every coin goes to the block producer (80%) and the proving pool (20%) | Homepage stats and Economics tiles; litepaper Supply, Economics | implemented | repo 6ac80a3; fork "igneum-node devnet v0"; consensus/core/src/igneum.rs, coinbase.rs |
cargo test -p kaspa-consensus-core igneum (8 pass: subsidy table, ramp, split, cap) and cargo test -p kaspa-consensus coinbase (8 pass); igneum-miner inspect 40; bench-log "igneum-node devnet v0" |
Coinbases on the devnet: 80/20 exact on 39 of 39 single-payee blocks, the 20% to the igneum-proving-pool-v0 output; the per-second schedule sums to under the 4,000,000,000 cap by less than 100 coins; 3,168,808,781 units per DAA second in years 0 to 2, halving at 63,115,200 DAA s. 3 October 2026, Apple M5 Max. The devnet genesis carries no allocation; the mainnet genesis does not exist yet, so the claim is about the code and the stated rule, not a launch that has happened |
none yet |
| 21 | The proving pool's 20% reaches shard provers and aggregators | Litepaper Economics; homepage "20% provers" | designed | spec 5.3 | None. The pool output exists (row 20); the payout from it against proof records is unwritten | The escrow accumulated on the simnet (92.55 IGN at the end of the v3 run) and nothing can draw it. Rule decided: per block, divided among shards by consensus proving cost, sortition to 8 provers for 10 s then open (spec 7.2) | none yet |
| 22 | The base fee is burned in full and the priority fee splits 80% to the miner and provers, 20% to the apps whose code ran | Homepage Economics caption and Build card; litepaper "Where fees go" | tested by the team | repo f5f8c80; fork worktree vendor/igneum-node-exec |
tools/evm-smoke/smoke.mjs receipt checks; bench-log "execution layer devnet v3" |
Transfer receipt: burnedProvingFee 200 gwei, minerTip 16,800 gwei (80%), unregistered developer share 4,200 gwei burned; contract call: 80% to the miner, 20% credited to the payee the constructor registered, balance delta equal. 3 October 2026, Apple M5 Max simnet. The provers' part of the 80% is not split out (no provers exist); the base fee stayed at the 1 gwei floor throughout |
none yet |
| 23 | No fee to any team, foundation or fund; 0 admin keys in consensus | Homepage Economics tiles and caption; litepaper "No fund, no foundation" and Governance | designed | spec 5.5, 5.6 (decided 3 October 2026); spec 08 | Reading: no coinbase output, fee route or consensus key in the fork names any party (coinbase.rs, docs/fork-divergence.md) |
The emission code has two outputs (row 20) and the fee code has three routes (row 22), none to a team. The 1% fee of the official client is a client setting, not a protocol rule, and is not implemented (no client exists). The release key of spec 08 signs client updates and holds no consensus power; its custody policy is open (O-8.1) | none yet |
| 24 | External proving jobs pay 90% to the provers who delivered and burn 10%, once settled in IGN | Homepage "IGN burned from jobs, phase two"; litepaper Proving and Economics | designed | spec 5.4 | None. Needs the proof bridge (spec 7.3, phase two) and the settlement switch (O-5.2) | At launch jobs are paid on the customer's chain in the customer's currency and nothing is burned (ledger P10). No job market code exists | none yet |
| 25 | The 4 billion cap, halving every two years, with a 30-day ramp from 10% | Homepage "4B IGN hard cap"; litepaper Supply and the emission chart | tested by the team | repo 6ac80a3; fork consensus/core/src/igneum.rs |
cargo test -p kaspa-consensus-core igneum; bench-log "igneum-node devnet v0" |
Ramp day 0 paid 10.03% of the full rate (317,767,704 units at DAA 806); the schedule table and the cap assert in the crate's own tests. 3 October 2026, Apple M5 Max. Base unit (8 or 18 decimals) is open (O-2.6); the spec was changed to follow the code's 365.25-day year (ledger E9) and a test that reads the published numbers back is still owed | none yet |
| 26 | A phone or browser verifies the chain from a locked checkpoint, at about 3.44 MB per day in checkpoint mode | Homepage "Browser checks Igneum" card (preview, commit f874f80); litepaper Building ("Light clients"), firsts row 6 |
designed | spec 10 (10.5 bytes per day: 3.44 MB at 1,000 voters, 6.68 MB at 10,000, derived, approximate); repo f874f80 for the browser card |
None for the byte figure; site/verify/ for the card. BLS verification on a phone and in WebAssembly is O-10.3; the full-header mode on a phone is O-10.4 |
The homepage card verifies the latest certified checkpoint's BLS certificate in the tab against a voter list from the node (light client v0, 3 October 2026). The byte figure is arithmetic on designed sizes (header 400 bytes, proof 400 bytes), measured nowhere; the proof the card would check does not exist (row 15) | none yet |
| 27 | The node survives malformed input, floods, withholding, partitions and eclipses | Litepaper Speed ("GHOSTDAG, the BlockDAG consensus proven on Kaspa"); spec 2 | tested by the team | repo 394030c; fork worktree vendor/igneum-node-harness; tools/harness/ |
tools/harness/ scenario runner against a private igneumd test network (ports 27200+); bench-log "consensus attack harness" |
63 malformed cases, node up on every one; timestamp bounds exact; withholding at 10%, 25%, 33% and 45% released every 5 blocks within 2 sigma of share; partitions of 120 s to 3,700 s healed to one chain in 10 s; eclipse victims rejoined in 10 s; 50x template, submit and mempool floods left template p95 under 4 ms. One FAIL: a 45% withholder releasing every 20 blocks took 50.7% of blues (bound 47.4%). 3 October 2026, Apple M5 Max, load 50 to 61. Finality and difficulty scenarios are stubs until those branches merge | none yet |
| 28 | Headers are validated cheaply before the lottery engine runs, so forged timestamps cannot force 256 MiB cache builds | Spec 2.4; ledger M15 | tested by the team | repo 0953ec7; fork worktree vendor/igneum-node-r3 branch r3-fixes at 5166ee26 |
measure_m15_attack_before_and_after (ignored test, release, --features igneum-pow); kaspa-pow 8, header_processor 1, p2p pow_guard 2 tests |
50 forged headers: before, 50 cold builds in 10,595 ms and the live day evicted; after, 0 builds, all 50 rejected in 14 ms. 3 October 2026, Apple M5 Max under load 60 to 110. Measured through the validate path with skip_proof_of_work, not the daemon RPC; not merged into the main fork branch |
none yet |
Count by status
| Status | Rows |
|---|---|
| designed | 7 (rows 15, 16, 17, 21, 23, 24, 26) |
| implemented | 3 (rows 2, 9, 20) |
| tested by the team | 18 (rows 1, 3, 4, 5, 6, 7, 8, 10, 11, 12, 13, 14, 18, 19, 22, 25, 27, 28) |
| reproduced externally | 0 |
| reviewed independently | 0 |
28 rows. The rendered page is site/evidence.html, kept in step by hand with this file; the bench page is generated, this one is not, because its text is judgement, not a log.
What would move a row
| From | To | What it takes |
|---|---|---|
| designed | implemented | Code in this repository with test vectors that pass |
| implemented | tested by the team | A bench-log entry with the machine, the date, the command and the number |
| tested by the team | reproduced externally | The repository public (January 2027), the command published, and a third party's run with the same result, linked from the row |
| reproduced externally | reviewed independently | A named reviewer's published finding on that version. Funding for review is docs/plans/funding.md |
| any | the row's status falls back | A new version of the code or rule the row names |