docs/plans/cryptanalysis.md: the project lead's 6 October 2026 decision (an outside team attacks class v4 after a week of real hash, bounded at USD 80,000 to 160,000) as a procurement plan. Scope over the generator, the mixer and chain, the latency-shadow ladder, the verifier bound, the era draw, the chip model's inputs and an ASIC and FPGA cost estimate; finality and the proof system out. Three fixed-price lots (firm, academic group, ASIC house), the prize question stated against the NO device bounty rule for the project lead to decide, everything published whole. Eight fits with comparable engagements, bases, contact pages and precedent prices (the four RandomX audits, ProgPoW, Zcash, Grin; the Antminer X9 as the lesson). Flip after publish 2 at 00:43 UK on 7 October; earliest start 14 or 15 October 2026, 09:00 UK; the freeze list. Three price points. A pseudonymous outreach email for approval. No contact made. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
54 KiB
Outside cryptanalysis of the Igneum hash class: the procurement plan
6 to 7 October 2026 (written 23:00 to 01:00 UK), the cryptanalysis lane (branch cryptanalysis, worktree igneum-wt-cryptanalysis, from master 631f505). the project lead's decision of 6 October 2026, 23:2x UK (docs/plans/ledger-decisions.md, the seven questions, item 6): "Yes. An outside team attacks the hash class after class v4 has run a week of real hash; bounded (lane 2's USD 80,000 to 160,000); the procurement plan is owed." This is that plan. Nothing here is contacted, commissioned, paid or mailed; every contact waits for the project lead's explicit go, one contact at a time. Every dollar figure cites its source or is marked approximate. This file is an operations document and is not on the public export list (tools/ci/identity-check.sh exports docs/spec, docs/analysis and the named files; docs/plans is not among them).
What this plan builds on, read in full: the mixer brief of docs/plans/funding.md (section B, 6 October 2026: target B1, ranked breaks B2, deliverables B3, suite B4, acceptance B5, candidates B6, risk B7, timing B8), docs/analysis/horizon/algorithm.md (lane 2: the chip model on the 6 October numbers, the N ladder, the era draw, the verifier proxy, proposal 8 "fund the k question"), docs/analysis/horizon/new-pow.md (lane 8, the class v5 candidates), docs/plans/counter-asic-3.md, -status.md (gates P1 and P2), -node.md, -reserve.md, -derivation.md, docs/plans/release-0.3.15.md (worktree igneum-wt-ship0315: the two publishes and the signal flip), docs/analysis/chip-model-v3.md sections 1 to 5, docs/analysis/latency-shadow-2026-10-06.md, docs/plans/era-layout.md section 8, docs/fud-ledger.md M1, M7, M22, docs/plans/ledger-decisions.md (the NO bounty outcome of 17:35 UTC and the standing decisions of 22:3x and 23:2x UK), igneum-pow/src/generator.rs (GENERATOR_VERSION_V4 = 4, V4_CLASS = mx8 + ShadowClass { instrs: 256, reps: 27 }), igneum-pow/Cargo.toml (crate version 0.2.0).
0. One page
| What is bought | Two paid, independent attacks on the hash class that ships (class v4, generator 4), plus one paper chip-design estimate from an ASIC house, against a frozen target and the published chip model. Not a new puzzle (lane 8 owns that), not the finality rule, not the proof system |
| Who | Lot A: one firm with person-days for the structural attacks (the mixer, the chained cache, the shadow block, the acceptance rule, the verifier bound). Lot B: one academic group for the models (time-memory trade-off, the draw census, the era draw, the ladder). Lot C: one ASIC estimation house for k, area, NRE and unit cost at N5 and 28 nm. Shortlist in section 2; nobody has been contacted |
| Shape | Three fixed-price lots, each with a stated person-day bound and a timebox; a report published whole, pass or fail, in the ledger, with its fix beside every finding. A cryptanalysis prize is a separate question for the project lead (section 3.3): the NO bounty rule of 6 October 17:35 UTC is a NO DEVICE bounty rule by its text, and the same outcome left "one cryptanalysis prize of USD 50,000 ... escrowed before it is named" as the project lead's call later |
| When | 0.3.15's publish 2 landed at 00:43 UK on 7 October 2026; class v4 flips at the floor (about 04:45 UK on 7 October) or by signal inside the one-day window (by about 00:45 UK on 8 October). Seven days of real class v4 hash end seven days after the flip hour. The freeze commit is tagged the morning the week closes; the earliest engagement start is Wednesday 14 October 2026, 09:00 UK if the flip was at the floor, Thursday 15 October 2026, 09:00 UK otherwise, and 15 October is the date to quote until the flip hour is read from the chain (section 4). Firms set their own calendars: the RandomX reviews ran 3 to 6 weeks each and about 9 weeks from commission to the last report |
| Budget | Low USD 80,000 (Lot A short, Lot B timeboxed, Lot C as a 10-day estimate), base USD 120,000, high USD 160,000 (Lot A at 40 person-days, Lot B at 30, Lot C with a synthesised core at two nodes). Section 5 prices each lot from the public precedents. The whole engagement is one to two weeks of year-1 miner emission at the low price input (funding.md B8) |
| What the project lead does | (1) approve or amend the scope (section 1); (2) tick the contacts he permits, in order (section 2); (3) decide the prize question (section 3.3); (4) approve the outreach email (section 6) and the sending address; (5) confirm the budget point (section 5). Nothing moves without each |
1. Scope
1.1 The target: what ships
The target is the hash class the chain runs after 0.3.15's flip, frozen at one commit (section 4.2). It is not the paper version.
| Piece | Exactly what the team attacks | Where it is defined |
|---|---|---|
| The generator's program distribution (generator 4) | 64 base instructions with 16 load slots drawn as a uniform 16-subset of instructions 1 to 63; ten non-load families at the weights of spec 1.4.2 (perturbed by up to 2 points per era); 8 registers; 592 draws per program from a 256-bit seed; the acceptance rule 1.4.6 (a) to (c) with redraw; the class v4 shadow block: 256 ALU instructions drawn after the base program, executed 27 times at the end of every iteration (55,296 shadow instructions per hash, about 100,000 counted ops); the output fold. Questions: weak-program selection (a miner or a chip that skips seeds), program-class distinguishers, acceptance bypass with address steering, the 39 edge disagreements, header grinding for DRAM locality, and whether the shadow block compresses (constant folding, dead registers, linear sub-blocks, common subexpressions across the 27 repetitions) so that a chip pays fewer than N ops | spec docs/spec/01-lottery-hash.md 1.4, 1.4.6, 1.7; igneum-pow/src/generator.rs (V4_CLASS, ShadowClass), accept.rs, verify.rs; docs/analysis/weak-program-census-2026-10-03.md; docs/analysis/latency-shadow-2026-10-06.md section 2 |
The memory-hard dataset: mixer M_r, the chained cache, item derivation |
Unchanged from the mixer brief: ChaCha12 cache fill in 2^16 segments of 64 chained lines; the ARX-multiply mixer with per-day ROT, MUL, RC from a 64-bit SplitMix64 seed; m = 8, 72 applications per item, 8 dependent cache reads; 128 dataset loads per hash over at least 2^26 words. Ranks 1 to 6 of funding.md B2 stand word for word, with the acceptance criteria of B5 |
funding.md B1, B2, B5; spec 1.8; igneum-pow/src/memhard.rs |
| The latency-shadow dataset and its ladder | The measured rungs (M5 Max, RTX 5090, RTX 4070, RX 9070 XT at N = 930, 49,700, 102,100, 130,000, 150,800, 199,600, 330,700 counted ops; the 11 pJ per counted op marginal on the 5090; the cards' 5 percent bind points) and the proposed genesis ladder {100,000; 130,000; 200,000; 330,000; 650,000; 1,000,000}, floor 100,000, ceiling set by the verifier, each step by 90 percent of blue blocks over 7 days. Questions: does the energy-per-hash law E_v3 + N x 11 pJ x k hold for a chip (is k bounded below by anything structural); can the ladder's signal be gamed by a chip owner (step down, never up); does any rung break the honest cards' 5 percent rule in a way the measurements missed; what the shadow mix's weights give a fixed datapath | docs/analysis/latency-shadow-2026-10-06.md sections 3, 5, 6; docs/analysis/horizon/algorithm.md 5.3, 5.3a, proposal 5; sim/horizon/algorithm/model.py --section ladder; docs/bench-log.md "Counter ASIC 3.0" entries |
| The verifier bound | The 10 ms per 32-lane warp gate on a 2019-class core, with the measured proxies (box one core 5.06 ms cold, half-core 8.23 ms at class v4; the 2.5x rule). Questions: a worst-case program for the verifier (the acceptance rule bounds the miner's side, not the verifier's); header-flood cost per core; verifier and miner asymmetry a pool or node attacker exploits; whether the bound still holds at the ladder's ceiling | algorithm.md 3.3, 5.5; spec 1.9; igneum-pow/src/verify.rs; O-1.14 |
| The era draw | One SplitMix64 stream from the era seed E_n (the 1-hour class-group VDF of a certified checkpoint) draws the op-weight perturbation, the fold rotations, the epoch_len placeholder, the load width (pinned), the stride multiplier M (odd) and rotation R, the four interleave bit positions. Questions: bias and grinding (the two routes priced in algorithm.md 5.4: forging the checkpoint, re-rolling by withholding), weak draws (the stride bijection, the all-equal ROT draw, low-weight M), the 64-bit seeding of the day-key stream, and what the draw assumes of the VDF (a written argument only; the VDF's own delay soundness belongs to the finality review row of funding.md) |
spec 1.13.1, spec 04-seeds-and-vdf.md 4.4 and 4.6; docs/plans/era-layout.md sections 1 and 8; algorithm.md 5.4 |
| The chip model's assumptions | Every input of chip-model-v3.md section 1 and 5.1 and algorithm.md 3.2 and 4: 50 T op/s and the 3x fixed-function factor for the recompute chip; the f = 1 stored-dataset chip's random-read ceilings (GDDR7 21.3 G reads/s, HBM3 one and eight stacks, HBM4 per JESD270-4), its energy per read, the 11 pJ per counted op honest marginal, k in 0.3 to 1.5, two-year amortisation at USD 0.10 per kWh, the silicon prices (sram-mirror.md USD 0.36 per mm^2 at N5, approximate), the JEDEC tFAW reading of the FPGA lane. Deliverable: each input confirmed, moved (with the new value and its source) or unsupported |
chip-model-v3.md 1, 5.1 to 5.6, 5.9; algorithm.md 3.2, 4, 5.1; docs/analysis/sram-mirror.md; docs/analysis/m16-recompute-attacker-2026-10-05.md |
| The ASIC and FPGA cost model | A paper design of the chip the model says anyone would build: a commodity GDDR7 or HBM3 controller feeding a 14,000-lane (approx) SIMD array that runs a random 32-lane program with warp shuffles for N counted ops per hash, at N5 and at 28 nm. Wanted: energy per counted op (k against the 5090's 11 pJ) with a range and the method (synthesis of one lane and the shuffle crossbar, or a published-library estimate), area, NRE, unit cost at 1,000 and 10,000 units, time to silicon, and the same for the soft-overlay HBM2 FPGA (the reads-in-flight ceiling against the measured 2.4 G reads/s) | algorithm.md 5.1 (the FPGA table), 5.3 (the chip floor per op), proposal 8; counter-asic-3-reserve.md section 3 (adders per lane per family) |
1.2 Out of scope, and the argument
| Out | Why | Where it is reviewed instead |
|---|---|---|
| The finality signature scheme (BLS vote keys, the aggregator VRF, the 2/3 lock) and the finality rule | A consensus rule, not a hash property; it has its own paid review row ("Independent review: finality rule v2", USD 50,000 to 100,000) and gate 3 | funding.md section 2; docs/spec/03-finality.md |
The proof system (SP1 behind the ProofSystem interface) and the chunked proving protocol |
Proving, kept separate from the lottery by design (the Aleo lesson); its own audit row before mainnet | funding.md "execution layer and proving integration" |
| The VDF implementation (class-group arithmetic, chiavdf) | The era draw assumes a delay function; the team writes down what it assumes and stops there. Reviewing the VDF code is the contracted cryptographer's O-4.1 line | funding.md development row; spec 04 |
| The node fork (p2p, difficulty, header validation) | The node audit row | funding.md; docs/fork-divergence.md |
Class v5 candidates (mx8 + sh256x35 with the shuffle-heavy table; scheme C "sd1", the dataset from stored state) |
the project lead's rule: the team attacks what ships. A candidate is attacked when it is a class behind its switch with gate packs. If Lot A has days left at the end, scheme C's item construction is the first optional extra, because it changes the derivation the whole brief targets | algorithm.md 5.3, 5a; new-pow.md 3.3, 6 |
One argument for widening, for the project lead to accept or refuse: the day-key rule. Today the day key is the calendar (interim rule O-1.10) and the proposed final rule ties it to the day's first epoch seed (a VDF output). If the final rule lands before the freeze, the team attacks it; if not, the team is told the interim rule is interim and the proposed rule is attacked on paper (B2 rank 6). Either way no second engagement is needed for it.
1.3 What the team is asked to deliver
| Deliverable | Content | Lot |
|---|---|---|
| The written report | One verdict per question of 1.1 (the six B2 ranks plus the shadow block, the ladder, the verifier bound, the era draw, the model inputs), each with the person-days spent, the tools (differential and linear trails, rotational-XOR, SAT or MILP on reduced rounds, pebbling bounds, census code), the reduced-round or reduced-size margin reached, and a severity in the reviewer's own scale. "No shortcut found" counts only with its effort bound, in the style of the four RandomX reports | A, B |
| Reproducible attacks | Every shortcut, trade-off, census, steering search or compression the reviewer wrote, runnable against igneum-pow at the frozen commit on the pinned class v4 packs, with the measured gain beside the honest path; any test the reviewer adds goes into igneum-pow/tests/ |
A, B |
| The soundness suite re-run | funding.md B4 on the reviewer's machine with the counts, plus the class v4 additions (the shadow fuzz, edge, stats and determinism runs at S = 256, R = 27) |
A |
| A chip-design estimate | A paper design with the numbers of 1.1's last row; k with a range and the method; the FPGA overlay row; a one-page statement of what would have to be true of a fab, a memory vendor and a controller IP for the design to be built | C |
| The verdict against the published chip model | A table over every input of chip-model-v3.md 1 and 5.1 and algorithm.md 3.2: confirmed, moved (new value, source) or unsupported; the headline "2.1x per joule over the 5090 at class v4 and k = 1" (algorithm.md section 8 item 2) either stands with its bound or is replaced by the team's number with theirs |
C, with A and B's inputs |
| Recommendations | On mixer_mult (8 or 16), the rotation draw bounds, the shadow weight table, the ladder's step rule and ceiling, the verifier gate, each stated against the finding that motivates it |
A, B |
1.4 The acceptance test
Two tests, kept apart: whether the engagement is accepted (we pay), and whether the hash passes (what we publish).
The engagement is accepted when: every question in 1.1 carries a verdict with person-days and named tools; every claimed gain runs on the pinned packs at the frozen commit and reproduces on one of our cards or the box; Lot C's k carries a range, a method and a node; the model-input table covers every row; the report is publishable whole under the reviewer's name (or anonymised at their choice, stated in the contract). A report that says "secure" with no effort bound is returned once; the timebox does not extend.
The hash passes when the reports state: (1) no method to evaluate the mixer's 8 keyed applications in fewer than 8x the single-application cost, nor the shadow block's 27 repetitions in fewer than 27x, after the stated search; (2) no derivation of cache line (s, j) in fewer than j + 1 block evaluations without an earlier line, and the storage-against-recompute curve from f = 1/64 to 1 drawn; (3) the weak-day fraction with any gain over 1.1x under 2^-20 per day (the threshold proposed in B5, not decided); (4) the line-index and item distributions within 6 sigma of uniform on the stated sample sizes, and no hot set under 1 percent of items among 10^6 passing seeds; (5) the era draw unbiasable below 20 days of 100 percent hash and no drawn parameter that makes a chip easier; (6) the verifier under 10 ms per warp cold on the O-1.14 core (the half-core proxy until it lands) on the worst program the team finds; (7) Lot C's per-joule edge of the f = 1 chip over the RTX 5090 bench row at class v4 at or under the published 2.1x at k = 1, or the published model corrected to their number and the public sentence re-cut (docs/evidence.md row 17). Anything else is a finding, and a finding is not a failure of the engagement: it is the reason the engagement exists. What a finding moves is in 3.4.
2. Who
The lesson that shapes the list, read 6 to 7 October 2026: RandomX bought four audits in 2019 (about USD 146,000, section 5.1) and shipped on Monero in November 2019; in July 2026 Bitmain listed the Antminer X9, a RandomX ASIC at 1 MH/s and 2,472 W (about 2.47 J per KH, about USD 5,600; monero-project/monero issue 10270), and RandomX v2.0 (released 25 March 2026, https://github.com/tevador/RandomX/releases/tag/v2.0) carries no published external audit. The four 2019 reviews looked for shortcuts and found none; nobody was paid to price the chip. That is why this plan carries Lot C beside Lots A and B, and why Lot C's verdict against the chip model is a deliverable and not a courtesy. Every name below is a candidate; nobody has been contacted, and every contact waits for the project lead's go. Price bands are from the public precedents of section 5.1 and are approximate; "time" is the calendar the comparable engagement took.
2.1 Firms (Lot A, and the generator and verifier questions)
| Candidate | Comparable engagement (URL) | Strong at | Base | Public contact | Price band and time (from precedent, approximate) |
|---|---|---|---|---|---|
| X41 D-Sec | RandomX 2019: 30 person-days, 3 consultants, with an FPGA and ASIC feasibility section in the report; https://x41-dsec.de/static/reports/X41-RandomX-Audit-2019-Final-Report-Public.pdf | Code-level cryptanalysis and hardware reasoning in one shop; the acceptance rule's implementation, the verifier, the shadow block | Aachen, Germany | https://x41-dsec.de/contact/ | EUR 42,000 for 30 person-days in 2019 (EUR 1,400 to 1,555 a day); about EUR 55,000 to 65,000 for 30 to 40 days now, approximate; 4 weeks of calendar |
| Quarkslab (Airbus-owned since 2026; unverified) | RandomX 2019: 32 person-days including a 10-day algorithmic-optimisation search; https://blog.quarkslab.com/security-audit-of-monero-randomx.html | The deepest of the four 2019 reviews by person-days; the optimisation-search shape is exactly rank 1 and the shadow block's compressibility | Paris, France | https://www.quarkslab.com/contact-quarkslab-cybersecurity-company/ | USD 52,800 for 32 person-days in 2019 at USD 1,650 a day with a public report; about USD 65,000 to 85,000 for 32 to 40 days now, approximate; 3 to 4 weeks |
| Trail of Bits | RandomX 2019: two engineer-weeks on the program generator's randomness; https://github.com/tevador/RandomX/blob/master/audits/Report-TrailOfBits.pdf; Monero FCMP++ cryptography implementation review, two engineer-weeks via MAGIC Grants bidding, August 2026, https://magicgrants.org/2026/08/17/Monero-FCMP-Cryptography-Implementation-ToB | The generator's distribution and bias, the seed and draw code; fast | United States | https://www.trailofbits.com/contact/ | USD 14,000 an engineer-week discounted in 2019 (16,000 list); USD 700 an hour in a 2025 application, so about USD 28,000 an engineer-week now; 2 to 3 weeks buys USD 56,000 to 84,000; a third-party "USD 25,000 per engineer-week" figure is unverified |
| Least Authority | ProgPoW algorithm audit 2019: the only published ASIC-resistance review of a PoW algorithm, 7 researchers including an FPGA engineer, about 8 weeks; https://leastauthority.com/static/publications/LeastAuthority-ProgPow-Algorithm-Final-Audit-Report.pdf | The ASIC-resistance question as a whole (their suggestion 5 was "watch ML hardware", their light-evaluation attack named the recompute chip); the chip model's assumptions | Berlin, Germany | https://leastauthority.com/security-consulting/ | Fee never published (the ECH Gitcoin grant was capped at USD 50,000 for both ProgPoW audits); the 2018 Zcash reviews ran 3 to 5 researchers over 4 to 10 weeks; price by quote, approximate band USD 60,000 to 100,000 for a 6-week review |
| Kudelski Security | RandomX 2019: 6 person-days, design level, "weaker authorized parameters" as a stated goal; https://github.com/tevador/RandomX/blob/master/audits/Report-Kudelski.pdf | Short design-level review; rank 3 (the weak draws) | Cheseaux, Switzerland | https://kudelskisecurity.com/services/ai-emerging-technology/blockchain-security-assessment | CHF 18,250 for 6 person-days in 2019 (about CHF 3,000 a day); the 2019 reviewer (Aumasson) has since left, so the bench strength on ARX is unverified; a 6 to 10 day opinion about CHF 20,000 to 35,000 now, approximate; 3 weeks |
| NCC Group Cryptography Services | Zcash Overwinter and Sapling 2018 (40 person-days), Zebra 2023 (60 person-days, 5 consultants), FROST 2023 (25 person-days); https://www.nccgroup.com/media/bw3nq0vm/_ncc_group_zcashfoundation_e005955_report_2023-06-27_v10.pdf | Large bench, published effort sizes, consensus-code depth | Manchester, United Kingdom and United States | https://www.nccgroup.com/technical-assurance/cryptography-encryption/cryptography-services/ | Fees never published; declined Grin in 2019 for want of a legal entity and fiat (Igneum Labs LTD answers both); band by quote, approximately USD 3,000 to 4,000 a person-day, so USD 75,000 to 120,000 for 25 to 30 days; 4 to 6 weeks plus a retest |
2.2 Academic groups (Lot B, and a second opinion on rank 1)
| Candidate | Comparable work (URL) | Strong at | Base | Public contact | Price band and time (approximate) |
|---|---|---|---|---|---|
| Jeremiah Blocki (Purdue) with Ling Ren (UIUC) | "Efficiently computing data-independent memory-hard functions" and the depth-robust attacks on Argon2i, https://eprint.iacr.org/2016/759; bandwidth-hard functions for ASIC resistance (Ren and Devadas, TCC 2017) | The parallel cumulative-memory model for rank 2; the energy model of bandwidth-hardness is the ladder's law in academic form | United States | university pages | A funded research contract: about USD 1,000 to 1,500 a day for 20 to 30 days, USD 25,000 to 45,000, approximate; 6 to 10 weeks of calendar |
| Itai Dinur (Ben-Gurion University) | The MTP break: a 2 GiB Argon2d proof of work reduced to under 1 MB by address steering before launch, https://eprint.iacr.org/2017/497 | Rank 2 and rank 5 are his attack on a chained memory with data-dependent reads | Israel | university page | the same band; a timeboxed study with a public report, 6 to 10 weeks |
| Gaetan Leurent (Inria, COSMIQ) or Maria Eichlseder (TU Graz) | ARX differential tools and the ChaCha differential-linear line, https://eprint.iacr.org/2021/224 | Rank 1's round margin: how many ChaCha-shaped double rounds with drawn rotations a distinguisher reaches, and the shadow block's ARX mix | France; Austria | institute pages | a short opinion, 10 to 15 days, USD 12,000 to 25,000, approximate; 4 to 6 weeks |
| Alex Biryukov and the CryptoLUX group (University of Luxembourg) | Argon2 and Equihash; the ranking trade-off attack on Lyra2, yescrypt and Argon2, https://eprint.iacr.org/2015/227 | The designer's side of rank 2 and the draw census (they have been on both ends of a memory-hard break) | Luxembourg | group page | the same research-contract band; the group's publication cadence makes a 10-week timebox realistic |
2.3 ASIC estimation (Lot C)
No vendor publishes a price for a paper design study; the bands are from the Europractice 2026 price list (https://europractice-ic.com/schedules-prices-2026/: GF 22FDX multi-project wafer EUR 21,800 to 23,980 per mm^2, minimum 0.8 mm^2, so real silicon starts near EUR 14,000 plus the design) and from design-consultancy day rates from memory, approximate.
| Candidate | Comparable (URL) | Strong at | Base | Public contact | Price band and time |
|---|---|---|---|---|---|
| A Bob Rao-style analytic hardware audit, bought from one of the houses below or from an independent | The ProgPoW hardware audit, 6 September 2019, https://github.com/ethcatherders/progpow-audit | The chip model's assumptions, line by line, from a chip architect's side; fast | low tens of thousands USD, approximate; 2 to 3 weeks | ||
| Aion Silicon (Sondrel, rebranded April 2025) | Mid-size ASIC design house, architecture-phase feasibility at advanced nodes, https://aionsilicon.com/press-release/sondrel-rebrands-as-aion-silicon/ | A synthesised lane and crossbar on OpenROAD with ASAP7 or on GF 22FDX, energy per op with a written J per hash, NRE and unit cost at volume | United Kingdom | site contact page | USD 30,000 to 80,000 for a synthesised core with a written energy figure, approximate; 4 to 8 weeks |
| Fidus Systems | ASIC and FPGA design house with a named feasibility-analysis service, https://fidus.com/services/asic-design-verification-validation/ | The same, plus the HBM2 FPGA overlay row (an FPGA house measures the reads-in-flight ceiling on real hardware) | Canada | site contact page | the same band |
| EASii IC | ASIC design house with a named "technical and financial feasibility studies" service, https://easii-ic.com/en/asic-design-house/ | The same, with Europractice access for a 22 nm shuttle if the project lead ever wants silicon | France | site contact page | the same band; plus about EUR 14,000 for a minimum 22FDX shuttle slot if silicon is wanted (not proposed) |
| ChipFoundry (SKY130 shuttle) | USD 14,950 per project on SKY130 (the chipIgnite successor; Efabless shut down in 2025), https://chipfoundry.io/faqs | A 130 nm proof of a datapath, not an energy figure at a modern node | not proposed: the node is 20 years from N5 and the number would not transfer |
Conflicted or unavailable, named so nobody proposes them later: Linzhi (dormant since 2020), Innosilicon and Bitmain (chip vendors; a vendor's estimate of its own market is not independent), the ProgPoW author now at Block building ASICs (a conflict by the plan's own rule), Imperas, Efabless and Adesto (gone or absorbed). Cheaper alternates with a public record, not in the eight: Cypher Stack (Monero's regular review contractor, USD 100 an hour in a 2021 CCS proposal, https://ccs.getmonero.org/proposals/cypherstack-sarang-triptych-research.html; security proofs rather than PoW attacks) and CryptoExperts (Paris, formal evaluation, https://www.cryptoexperts.com/services/evaluation/, no public price). Intermediaries that can run a bidding round and pay fiat without naming the sponsor early: OSTIF (https://ostif.org/get-an-audit/, which ran the 2019 RandomX round: four bids, a public vote, fiat handled; its own page cites a USD 71,000 negotiated price against a USD 143,000 bid, https://ostif.org/the-ostif-difference/) and MAGIC Grants (the 2026 Trail of Bits FCMP++ review). An intermediary suits a pseudonymous founder and costs a fee and some weeks; the direct route is the email of section 6.
2.4 The eight fits, ranked for this job
| # | Candidate | Lot | Why, in one line |
|---|---|---|---|
| 1 | X41 D-Sec | A | Cryptanalysis and hardware reasoning in one report in 2019; the right shape for the shadow block, the acceptance rule and the verifier together |
| 2 | Quarkslab | A | The 10-day optimisation search of 2019 is rank 1 and the shadow's compressibility; the deepest bench by person-days |
| 3 | Trail of Bits | A (narrow) | The generator's randomness and bias in two engineer-weeks; expensive per day, fast, a name the public knows from RandomX |
| 4 | Least Authority | A or the chip-model verdict | The only published ASIC-resistance audit of a PoW algorithm; named the recompute chip before this project did |
| 5 | Blocki with Ren | B | The cumulative-memory and bandwidth-energy models are the two laws the ladder and the chain rest on |
| 6 | Dinur | B | The MTP break is the attack rank 2 and rank 5 fear, on a construction of the same shape |
| 7 | Leurent or Eichlseder | B (short opinion) | The ARX round margin of the mixer and the shadow mix is their published question |
| 8 | A Bob Rao-style analytic study plus a synthesised core at a mid-size house (Aion Silicon, Fidus or EASii IC) | C | The one number nothing in the project can measure, k, with a method behind it |
Recommended pairing at the base price point: 1 or 2 for Lot A (ask both for a quote; take the one whose proposal names the shadow block's compressibility as a line item), 5 and 6 for Lot B (Blocki and Ren for the models, Dinur for the attack; or one of them with 7 as a short rank 1 opinion if Lot A's round margin comes back thin), 8 for Lot C. Trail of Bits and Least Authority are the alternates for Lot A if the first two are booked or decline; Kudelski and NCC are the alternates behind them.
3. The shape
3.1 Three fixed-price lots
| Lot | What | Bound | Why fixed price |
|---|---|---|---|
| A, the firm | 1.1 rows 1, 2, 4 (the structural attacks: the mixer, the chain, the shadow block's compressibility, the acceptance rule, header grinding, the verifier's worst case); the suite re-run; the recommendations on mixer_mult and the shadow table |
25 to 40 person-days, 3 to 6 weeks of calendar (the X41 and Quarkslab pattern of 2019) | A firm quotes person-days against a scope; a time-and-materials review of a hash has no natural end |
| B, the academic group | 1.1 rows 2 (the pebbling model of the chain), 3 (the ladder's law and its signal), 5 (the era draw, the draw census), the uniformity censuses | 20 to 30 person-days over 4 to 8 weeks of calendar (academic calendars are longer; a timebox with a named end date) | A group paid for a timeboxed study with a public report, the CCS pattern |
| C, the ASIC house | 1.1 rows 6 and 7: the paper design, k at two nodes, area, NRE, unit cost, the FPGA row, the model-input verdict table | 10 to 20 engineer-days | A design study is a scoped estimate with a stated method; the number it produces (k) is the one nothing in the project can measure (algorithm.md proposal 8) |
Rules of the engagement, written into every contract: the target is the frozen commit and nothing later; the reviewer may ask for a parameter re-cut once, and the re-run (one further week) is priced in the fixed sum; the report is published whole, pass or fail (rule 2 of funding.md); the reviewer's attack code is published under the repository's licence; no reviewer holds an interest in a mining-hardware business for the chain, stated in writing; payment by the entity (Igneum Labs LTD, DIFC), never a person; half on signing, half on the report; no NDA is needed because everything the reviewer receives is on the public export list or will be.
Who is in parallel with whom: Lots A and B start together on the freeze; Lot C starts when A has reported its op counts for the shadow block and the mixer (about week 3), so the chip estimate prices the hash as it is after any shortcut, not before. If A finds a shortcut, C prices both the hash with and without the fix.
3.2 The reviewers do not meet the fix
A finding goes to the reviewer who found it with the proposed fix (a parameter, a draw bound, a shape, a ladder rule) and one question: does the fix close it, in your own words, for the public report. The fix itself is built here (hours, funding.md B7: the x8 re-cut was one commit) and rolled through the class system (a class v5 behind its switch, by 95 percent signal, never a fixed height), never by the reviewer.
3.3 The prize question, for the project lead
The facts. On 6 October 2026 at 17:35 UTC the project lead ruled NO device bounty (ledger-decisions.md, outcomes item 1, corrected): "a team with a real 2x chip earns more mining than any bounty, so those tiers attract nobody"; every public mention of a bounty was struck. The same ruling kept one door open, in these words: "Optional, the project lead's call later: a single cryptanalysis prize of USD 50,000 for a published 2x+ shortcut in the mixer, the chained cache or the acceptance rule, escrowed before it is named." Rule 3 of funding.md stands: a bounty is announced only when it is escrowed.
Does a cryptanalysis prize fall under the NO bounty rule? By the rule's own reasoning, no: the rule's argument is that a chip's owner mines instead of claiming, and that argument is about a device. A shortcut is a result, not a device: a researcher who finds a 2x algebraic shortcut in the mixer cannot monetise it by mining without building the chip, so the prize is the only payment that buys disclosure over silence or sale. That is why Monero's community funded reviews and bounties for RandomX while never offering a device bounty, and why the ruling itself left the prize optional. By the rule's words, a public "bounty" sentence of any kind was struck from every page on 6 October, and the prize is a bounty by another name. Both readings are honest; the decision is the project lead's and this plan does not pre-empt it.
If the project lead says yes, the shape from precedent (the numbers are in section 5's precedent table): one prize, USD 50,000 (the figure in the ruling), for a published, reproducible shortcut of 2x or more in ops per hash against the frozen class (the mixer, the chained cache, the shadow block or the acceptance rule), or a bias of the era draw under 20 days of hash; judged by one of the paid reviewers on a day rate from the review line, never by the team; escrowed by the entity before the word "prize" appears anywhere; announced with the published reports, not before; no expiry; the first qualifying disclosure wins and the finding is published with its fix like every other. If the project lead says no, section 1.4's test and the public benchmark (M22's metrics) carry the claim alone, as the ruling says today.
3.4 What we publish
Everything, by the standing rules: a paid review is published whole, pass or fail, and linked from docs/evidence.md (rule 2 of funding.md); the ledger is public (docs/fud-fixes.md decision 1) and a row closes Conceded with its fix stated on the public page (the convention every M, F, E, P and X row follows).
| Item | Where | When |
|---|---|---|
| The three reports, as delivered (PDF or Markdown), with the reviewers' names or their chosen anonymity | docs/review/cryptanalysis/ on the public export list, mirrored to the public repository |
The day each lands |
| One ledger row per engagement (a new M row at the next free number when merged) carrying the verdicts, the effort bounds, each finding with its fix and the fix's class or switch | docs/fud-ledger.md; M1, M7 and M22 updated to point at it (M7 "no cryptographic analysis at all" moves from Conceded to the row's state) |
With each report |
docs/evidence.md: the hash rows move from "tested by the team" to "reviewed independently"; row 17 (the chip claim) re-cut to Lot C's number if it moves |
docs/evidence.md |
With Lot C's report |
| The scope, the frozen commit, the packs, the contracts' public terms (not the prices unless the project lead chooses; Monero published its costs and this plan recommends the same) | this file's public twin, docs/analysis/cryptanalysis-engagement.md, written at commission |
At commission |
| The litepaper's sentence "Open: no analysis of the lottery properties exists yet" replaced by the reviewed state | site/litepaper.html |
With the first report |
4. Timing
4.1 The week of real hash
The clock starts at the class v4 flip, not at the publish. 0.3.15's publish 1 (binaries on the thirteen-field object) ran on the evening of 6 October; publish 2 (the sixteen-field object with program_class_v4_activation_daa = the floor, publish DAA + 14,400 rounded up to the epoch, at least 10,800 ahead, and program_class_v4_signal_window_daa = 86,400) landed at 00:43 UK on 7 October 2026 (the coordinator's line). The class flips at the first epoch boundary after 95 percent of blue blocks in the window signal, or at the floor regardless (release-0.3.15.md section 2; counter-asic-3-status.md P2). At about one block a second the floor is about 4 hours after the publish and the full window is 24 hours, so the flip lands between about 04:45 UK on 7 October and about 00:45 UK on 8 October.
| Flip case | The flip | A week of class v4 hash closes | Earliest engagement start |
|---|---|---|---|
| At the floor (the whole fleet signalling or nobody signalling): about 7 October 2026, 04:45 to 06:00 UK | 7 October, early morning | 14 October 2026, 04:45 to 06:00 UK | Wednesday 14 October 2026, 09:00 UK |
| By signal later in the window | 7 October, daytime or evening | 14 October, the same clock hour | Thursday 15 October 2026, 09:00 UK |
| At the end of the window | up to 8 October, about 00:45 UK | 15 October, about 00:45 UK | Thursday 15 October 2026, 09:00 UK |
So the earliest start is Wednesday 14 October 2026, 09:00 UK, and Thursday 15 October 2026, 09:00 UK is the date to quote to a firm until the flip hour is read from the chain.
The flip hour is read from the chain (the first block with the v4 program id; igneum_getRecentBlocks in 0.3.16, the observer's class column until then), never from a report. Main checks it before this table is quoted to the project lead.
Why a week and not a day: M22's benchmark metric asks for at least 100 epochs per program distribution; at one epoch an hour a week is 168 epochs and 168 programs, enough for the per-program hash-rate spread, the detector's rows (tools/observer/detector.mjs) and the vote-weight record to be real data the team receives rather than numbers the team is told. The week also runs the ladder's rule on the live chain for 7 daily windows, the length of its own signal window.
4.2 What is frozen before the start
The freeze is one tagged commit on master, cryptanalysis-target-1, cut the morning the week closes, and one directory of artefacts the team downloads. Nothing in the list changes for the length of the engagement; a change is a new target and a priced re-run.
| Frozen item | Exactly what | Owner |
|---|---|---|
| The generator | igneum-pow at the tag: GENERATOR_VERSION_V4 = 4, V4_CLASS (mx8+sh256x27: LoadClass::MX8 with ShadowClass { instrs: 256, reps: 27 }), the acceptance rule, the verifier, the emitters; crate version bumped from 0.2.0 to 0.3.0 at the tag so the report cites a version, not only a hash |
the hash lane |
| The ladder list | The N ladder {100,000; 130,000; 200,000; 330,000; 650,000; 1,000,000}, floor 100,000, the ceiling as the spec states it at the tag (1,000,000 by the 2.5x rule, or the O-1.14 measured ceiling if the laptop run has landed; 370,000 is the half-core proxy's figure), the step rule (90 percent of blue blocks over 7 daily windows at a day boundary), written as PROPOSED or DECIDED in spec 01 with the decision date. If the project lead has not decided the ladder by the freeze, the team attacks the proposal as written and the report says so | the algorithm lane, the project lead's decision |
| The published chip model | chip-model-v3.md sections 1 to 5 and algorithm.md sections 3.2, 4, 5.1, 5.3a as they stand at the tag, plus sim/horizon/algorithm/model.py and the lane 7 frontier model; the evidence row 17 sentence |
the algorithm lane |
| The latency-shadow dataset | The bench-log entries and analysis files behind every rung in 1.1 row 3, plus the week's observer export (per-epoch program ids, hash-rate spread per card model, the detector rows) | the observer agent |
| The verifier bound | 10 ms per warp; the box proxy numbers; the O-1.14 laptop row if landed | the algorithm lane |
| The era draw | Spec 01 1.13.1, spec 04 4.4 and 4.6, era-layout.md, the six era packs; the day-key rule's state (interim or final) |
the hash lane |
| The reserve order | R0 dr368, R1 to R8 as recommended in algorithm.md 5.2 or as the project lead decides |
the project lead's decision |
| The dataset schedule | 2 GiB at genesis, 4 GiB at year 4, 8 GiB at year 12; the devnet's 1 GiB packs | decided |
| The packs and vectors | The class v4 gate packs (docs/plans/counter-asic-3-gate/), mx8-genesis, mx8-devnet-epoch0, the six era packs, the 96-vector sets and the 2^24 fingerprints per pack, the three vendors' bit-exact record |
the hash lane |
Owed before the freeze and not a precondition of it: the O-1.14 laptop run (2 hours of agent work, algorithm.md proposal 1) and the AWS F2 FPGA hour (proposal 2). Both make the target better and neither holds the date; the plan states which landed.
4.3 The calendar after the start
Firm calendars are theirs. From the RandomX pattern (CCS funded in May 2019; X41 ran 3 to 28 June; Trail of Bits reported 2 July; Kudelski 2 July; Quarkslab 30 July): about 10 weeks from commission to the last report. Outreach, quotes and contracts come before the start and take the firms' time, not ours: a contact the project lead ticks tonight can have a quote back in about a week, so the first contacts should go the week of 7 October if a start near 15 October is wanted; a firm's own backlog decides the real kickoff, and the RandomX round shows one to two weeks between a signed scope and the first engineer-day. The go checklist row (testnet-go.md, 9a per funding.md B8): the reports in hand before the last announced reset of testnet-1, so the vectors the testnet freezes are the reviewed ones; mainnet never opens without the published reports.
5. Budget
5.1 The public precedents (read 6 October 2026; primary sources where the URL is a report or a statement of work)
| Engagement | Year | Price as published | Effort | Calendar | Source |
|---|---|---|---|---|---|
| RandomX, Trail of Bits (paid by Arweave) | 2019 | USD 28,000; the statement of work's list rate USD 16,000 per engineer-week, discounted to 14,000 | 2 person-weeks | 20 May to 3 June; report 28 May | https://github.com/hyc/RandomxAudits (SoW-TrailOfBits.pdf); https://github.com/tevador/RandomX/blob/master/audits/Report-TrailOfBits.pdf |
| RandomX, X41 D-Sec | 2019 | EUR 42,000 fixed (about USD 46,900 at the CCS estimate) | 27 to 30 person-days, 3 consultants (about EUR 1,400 to 1,555 per person-day) | 3 to 28 June; final 5 July | SoW-X41.pdf; https://github.com/tevador/RandomX/blob/master/audits/Report-X41.pdf |
| RandomX, Kudelski Security | 2019 | CHF 18,250 fixed (17,500 engineering, 750 project management) | 6 person-days recorded; 3 calendar weeks estimated | snapshot 10 June; final 2 July | SoW-Kudelski.pdf; Report-Kudelski.pdf |
| RandomX, Quarkslab | 2019 | USD 52,800 excluding VAT; the SoW's USD 2,000 per day reduced to 1,650 for a public report | 32 person-days, 3 engineers | about 3 weeks; report 2 August | SoW-Quarkslab.pdf; Report-Quarkslab.pdf; https://blog.quarkslab.com/security-audit-of-monero-randomx.html |
| RandomX, the Monero CCS round | 2019 | 1,400 XMR asked at an assumed USD 85 (about USD 118,000) for the three Monero-funded audits; 1,293.8 XMR raised, funded 30 May 2019 (milestones Kudelski 215, X41 555, Quarkslab 625 XMR); all four audits about USD 146,000 | commission to last report: 30 May to 2 August, about 9 weeks | https://ccs.getmonero.org/proposals/RandomX-audit.html; https://ostif.org/four-audits-of-randomx-for-monero-and-arweave-have-been-completed-results/ | |
| ProgPoW, Least Authority (algorithm) and Bob Rao (hardware), Ethereum Cat Herders | 2019 | Gitcoin grant capped at USD 50,000 DAI, filled April 2019, "almost double" raised with matching, about 13,000 DAI refunded; the split between the two audits never published | Least Authority: 7 named researchers including one FPGA engineer, person-days not stated | code review 17 July to 14 August; final report 9 September (about 8 weeks); hardware report 6 September | https://leastauthority.com/static/publications/LeastAuthority-ProgPow-Algorithm-Final-Audit-Report.pdf; https://github.com/ethcatherders/progpow-audit |
| Zcash launch audits (NCC Group, Coinspect, Solar Designer's Equihash analysis) | 2016 | about USD 250,000 combined, "a quarter of the USD 1M raise" (CoinDesk); split not published | not stated | August to November 2016 | https://www.coindesk.com/markets/2016/09/09/inside-the-zcash-audit-why-the-anonymous-blockchain-project-spent-250k-on-a-trial-by-fire; https://www.openwall.com/articles/Zcash-Equihash-Analysis |
| Zcash Overwinter and Sapling, NCC Group | 2018 | not published | 40 person-days (20 + 20), 2 and 4 consultants | March to May 2018, retest September, public report January 2019 | https://www.nccgroup.com/media/v1kkxeae/_ncc_group_zcash2018_public_report_2019-01-30_v13.pdf |
| Zcash Sapling, Kudelski Security | 2018 | not published | about 70 hours | February to June 2018 | https://cybermashup.wordpress.com/wp-content/uploads/2018/08/zcash-audit.pdf |
| Zebra and FROST, NCC Group for the Zcash Foundation | 2023 | not published | 60 person-days, 5 consultants (Zebra); 25 person-days, 3 consultants (FROST) | spring and summer 2023 | https://www.nccgroup.com/media/bw3nq0vm/_ncc_group_zcashfoundation_e005955_report_2023-06-27_v10.pdf; https://www.nccgroup.com/media/m1yjijzn/_ncc_group_zcashfoundation_e008263_report_2023-10-20_v11-1.pdf |
| Grin security audit, Coinspect | 2019 | fund 17.28 BTC raised (about USD 66,500 in March 2019); Coinspect quoted USD 250 an hour for about 320 hours (USD 80,000), Quarkslab USD 1,650 a day for about 30 days (USD 49,500); NCC declined (no legal entity, no crypto payment) | about 320 hours | February 2019; report 18 October 2019 | https://grin.mw/sec_audit.html; https://github.com/mimblewimble/grin/issues/1609 |
| Current rate signals | 2025 to 2026 | Trail of Bits USD 700 an hour (Arbitrum ARDC v2 application, 2025); Cyfrin USD 20,000 to 30,000 per week (Zcash Community Grants application, 2025/26); OpenZeppelin about USD 23,100 per researcher-week (Venus, 2023) | https://forum.arbitrum.foundation/t/election-application-thread-v2-arbitrum-research-development-collective/27267/16; https://github.com/ZcashCommunityGrants/zcashcommunitygrants/issues/407 |
Prizes and bounties, for section 3.3: Chia's VDF competitions USD 100,000 announced per round (116,000 and 106,000 paid, 2019); Chia's proof-of-space competition USD 100,000 (2019); Zcash's open-source miner challenge USD 30,000 (2016); John Tromp's Cuckoo Cycle bounties USD 5,000 to 10,000 each (the linear time-memory trade-off bounty, raised from USD 500 to 10,000, was claimed and paid in April 2025; two siphash bounties open; a 1 BTC Apple-silicon bounty paid July 2026); the Password Hashing Competition and NIST's lightweight competition carried no prize money. Sources: https://www.chia.net/2019/04/04/chia-network-announces-2nd-vdf-competition-with-100000-in-total-prize-money/; https://zcashminers.org/challenge; https://github.com/tromp/cuckoo. So USD 50,000 for one prize sits between Tromp's single-result bounties and Chia's whole-competition purses, and above every PoW cryptanalysis prize ever paid for one result.
What the precedents say about rates: in 2019 a European firm cost USD 1,400 to 1,650 per person-day for a public report and a US firm USD 2,800 per engineer-day; by 2025 the US firms quote USD 4,000 to 5,600 a day (about double 2019), and no European firm has published a 2026 rate (funding.md's "raised by about a third" is therefore low for US firms and about right for European ones; both approximate). Nobody has published what the ProgPoW hardware audit cost, so Lot C has no PoW precedent and is priced from design-consultancy day rates from memory (approximate).
5.2 The three price points
| Lot | Low: USD 80,000 | Base: USD 120,000 | High: USD 160,000 |
|---|---|---|---|
| A, the firm | 25 person-days at about USD 2,000 (a European firm at a public-report rate, 2019 x 1.3, approximate): USD 50,000. Scope: B2 ranks 1, 2, 5 and the shadow block only | 32 person-days (the Quarkslab shape) at about USD 2,000: USD 65,000. Scope: all of 1.1 rows 1, 2, 4 | 40 person-days at about USD 2,100, or 2 to 3 engineer-weeks of a US firm at USD 28,000 a week on the narrow structural scope with the rest at a European firm: USD 85,000 |
| B, the academic group | 15 person-days timeboxed to the pebbling model, the draw census and the era draw (about USD 1,200 a day, approximate, the rate of a funded research contract rather than a consultancy): USD 18,000 | 25 person-days, adds the ladder's law and the uniformity censuses: USD 30,000 | 30 person-days, adds the acceptance-rule search over 10^6 seeds and a written review of the proposed day-key rule: USD 40,000 |
| C, the ASIC house | 6 to 8 engineer-days: a paper estimate from published cell libraries and the reads-in-flight model, k with a range at one node: USD 12,000 (approximate) | 12 engineer-days: one synthesised lane and the 32-lane shuffle crossbar at 28 nm on an open PDK, N5 by published scaling, NRE and unit cost at two volumes, the FPGA row: USD 25,000 | 20 engineer-days: the above plus a placed-and-routed lane with power from a gate-level simulation of three real class v4 programs, the controller's power from a vendor datasheet, the model-input verdict table in full: USD 35,000 |
| Total | USD 80,000 | USD 120,000 | USD 160,000 |
Inside each point and not extra: the one-week re-run after a parameter move (priced into each fixed sum), the day-rate judging of any finding, the publication. Outside every point: the optional USD 50,000 prize (escrowed separately, only if the project lead says yes), the F2 FPGA hour (USD 2 to 8), the O-1.14 laptop run (agent hours). Against funding.md section 2 the line keeps its USD 80,000 to 160,000 row; the review-and-audit bucket stays USD 290,000 to 570,000 with it; all approximate, and the coordinator re-totals when the point is chosen.
Which point this lane recommends: base. Low drops the ladder's law and the uniformity censuses, which are the two questions nothing in the project has measured, and buys a Lot C figure with no synthesis behind it, which is the one number the whole chip model turns on. High buys mostly calendar and a US firm's name. the project lead decides.
6. The outreach email, for the project lead's approval
Pseudonymous: the founder is one pseudonymous person working with AI systems (site/litepaper.html, "Who are you?"); the entity is Igneum Labs LTD, DIFC; no personal name anywhere; the only addresses are igneum.network ones. The address in use today is hello@igneum.network (the only one in the repository); this plan proposes a research@igneum.network mailbox for the engagements so the thread is separable, the project lead's call. The body is the same for every candidate; the bracketed line names the lot.
Subject: Paid, bounded cryptanalysis of a GPU proof-of-work hash (fixed scope, public report)
Hello,
We are Igneum, a GPU-mined layer 1 in development (igneum.network). The project is run by a pseudonymous founder; the software is shipped and contracts are signed by Igneum Labs LTD, Dubai International Financial Centre. We write to ask whether you would take a fixed-price engagement to attack our proof-of-work hash, with the report published in full whatever it finds.
The target is the hash class that runs on our development network today: a random-program GPU hash (a RandomX idea rebuilt for GPUs), a 2 GiB memory-hard dataset derived through an ARX-multiply mixer over a chained ChaCha12 cache, a block of about 100,000 counted ALU operations per hash hidden under the memory latency, a CPU verifier bounded at 10 ms per 32-lane warp, and an era draw of parameters from chain state. Everything is open source and specified; a chip model we published says what we think a purpose-built chip gains and where that model could be wrong. The target is frozen at one tagged commit with pinned test vectors and a week of real network data, and it does not move during the engagement.
[Lot A] We would like a cryptanalysis of the mixer, the chained cache, the shadow block and the program acceptance rule: shortcuts, time-memory trade-offs, weak parameter draws, address steering, the verifier's worst case. Each question comes with a stated acceptance criterion and what a break would hand a chip. [Lot B] We would like a timeboxed study of the memory-hard construction in the parallel cumulative-memory model, a census of the parameter draw space, and an analysis of the era draw and of our proposed difficulty ladder for the hidden work. [Lot C] We would like a paper chip-design estimate: the energy per counted operation, area, NRE and unit cost at two process nodes of a chip that stores the dataset in commodity memory and runs a random 32-lane program with shuffles, against the measured figures of an RTX 5090, and a verdict on each input of our published chip model.
What we ask for in return: a written report with one verdict per question and the effort spent on it, any attack code runnable against our crate on the pinned vectors, and your recommendations. The report is published whole, pass or fail, under your name or anonymised at your choice; your code is published under the repository's licence. We have a fixed budget band for the whole programme and would like a fixed-price proposal with the person-days and the calendar you would need. The earliest start on our side is 15 October 2026. We would also ask you to confirm in writing that you hold no interest in mining hardware for this chain.
If this is of interest, we will send the scope document, the specification, the crate, the packs and the chip model by reply. No NDA is needed: everything you would receive is public or will be.
Igneum Labs research@igneum.network igneum.network
Rules for sending, if the project lead approves: one contact per go, named in his reply; the email goes from the igneum.network mailbox through the Igneum Chrome profile ("[user] (igneum.network)"), never another brand's; no attachment on first contact (the scope follows on reply); every reply is logged in this file's section 7 with the date and the ask, never the quote's confidential terms on the public twin.
7. Contact log
| Date (UK) | Candidate | Lot | the project lead's go | Sent | Reply | Next |
|---|---|---|---|---|---|---|
Nothing has been sent. This table is empty by design until the project lead ticks a name.
8. Consequences per tier, and what this lane does next
Per tier, nothing changes on any card while the engagement runs: the hash is frozen, the cards' rates are the measured ones. What changes is the public claim's status and the chain's safety margin. The case a finding moves is funding.md B8's table (rank 1 at the class v2 cost: a chip at 7.4x with the factor, chips at 85 percent of hashrate within four months of a fork on the Monero precedent, every card's share of issuance about 0.15x): the engagement before the testnet's vectors freeze is what turns that case from a mainnet governance event into one commit and one signalled class change. For a pool user and a verifier: a verifier worst-case finding is a header-flood cost, fixed by a bound in the acceptance rule, no rate change. For the chain's security budget: Lot C's k decides whether "2.1x at class v4" is a number or a hope; if k comes back under 0.5 the ladder's next rung is the response and this plan's section 1.4 says so in advance.
Next for this lane: fill sections 2 and 5 from the research (this commit), then nothing until the project lead ticks a contact.