- 03-finality: Q2 participation from every vote seen in blocks (votes are block payload); 3.3.2 the eclipse case closed by the 56.7% floor with the sim v2 F2 numbers; 3.4.1 why aggregators cannot grind participation. - 07-execution (new): EVM semantics on the DAG, shard sortition (8 provers, 10 s, then open, no shard bond), bridges (none official, no bridged stablecoins at genesis, proof bridge with the consensus proof in phase two). - 08-client-security (new): reproducible builds, release key in genesis and in hardware, no silent updates, consensus only by 90% signalling, notarised builds, official sources with the hash, seed confirmed before mining, hardware wallet, the permanent seed line. - 00, 02, 05, README, 06: cross-references, O-2.8 removed, O-3.3, O-3.7, O-5.1, O-5.2, O-5.6 narrowed, O-8.1 added, counts kept at 60. - Ledger: eight Status lines, status table, count table, overclaims 38, 40, 71. - FUD fixes: rows 23, 26, 38, 62, 64, 66, 67, 70, 72, section 3 and 4. - Site: bridge and stablecoin sentences no longer launch features; the seed line wherever the app appears. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
9 KiB
Igneum protocol specification, section 5: fees, splits, burns, signalling
Spec version 0.1, 3 October 2026. Status of this section: Designed (design document, "The token", "Finality rule, version 2: Fees", decisions table "What do I get for being early?"). Nothing here is implemented or measured. Emission itself is section 2.5.
Two rules frame everything: there is no stake anywhere in consensus, and the protocol carries no fee to any team, foundation or fund. Not one unit of emission or of fees goes to a treasury, a fund, a founder or a stake. The development fund that earlier drafts carried (5% of tips and 5% of job fees under 60% signalling) was removed on 3 October 2026 (section 5.5).
5.1 Base fee
Designed. Every transaction pays a base fee in both gas dimensions:
| Dimension | What it meters | Who sets it |
|---|---|---|
| Execution gas | EVM execution, Ethereum's rule | Ethereum's EIP-1559-style base fee over the ordered sequence |
| Proving-cost gas | Proving cycles the transaction will cost the provers | A second base fee adjusted per block from the unproven backlog, smoothed over the difficulty window (section 2.3) so cards do not flip between hashing and proving every block |
The base fee in both dimensions is burned in full. A miner cannot stuff blocks with its own transactions for free; wash gas loses its whole base fee (ledger E3). The proving-cost budget per block is a consensus constant set from measured prover throughput (phase 2 gate: one shard on a 12 GB card in about 20 s, Target, unmeasured, ledger P1), so a transaction that is cheap to run and brutal to prove cannot stall the provers for everyone. How the node folds the proving-cost dimension into the quoted gas price so eth_estimateGas keeps working is fixed in section 7.1 (ledger P5, closed 3 October 2026).
5.2 Priority fee split
Designed. The priority fee (tip) of every executed transaction splits:
| Share | Recipient | Rule |
|---|---|---|
| 80% | Block producer and provers | The producer of the block in which the first copy executed (section 2.6) and the provers of that block, in the proportion the proving protocol defines (forward reference) |
| 20% | Developer | Attributed per call frame by gas consumed, to the developer address registered for the called contract at deployment. A frame in an unregistered contract sends its share to the burn |
No part of the tip is burned by rule; the burn is the base fee (5.1) and the unregistered developer share.
Per-call-frame attribution: a transaction that calls contract A, which calls B, which calls C, pays 20% of the tip in proportion to the gas each frame consumed, to A's, B's and C's registrations respectively. A frame's own gas excludes the gas of frames it called.
Factory rule: a contract deployed by another contract (CREATE or CREATE2 from a contract) inherits the deploying contract's registration unless it re-registers in the same transaction. A contract deployed from an externally owned account registers the address the deployment names, or none.
Self-dealing: a developer who also mines the including block collects 80% plus 20%, the whole tip, and still loses the whole base fee in both dimensions, so wash gas is a guaranteed loss; it can still inflate a "gas earned" figure on a leaderboard, so no explorer ranking should use raw developer share without a self-dealing filter (ledger E3; not a consensus rule).
5.3 Proving pool
Designed. The 20% emission share (section 2.5) and the provers' part of the 80% tip share are paid per block as a fixed amount for that block, divided among the block's shards by consensus proving cost, so a stuffed block earns no more than an honest one. Shards are not claimed first-come and carry no bond: each shard is assigned by sortition to 8 eligible provers for a 10-s exclusive window, then open to anyone, and the first valid proof included in a block is paid (section 7.2, decided 3 October 2026, ledger P8, C9). The parameters 8 and 10 s are set on the phase 4 devnet (O-5.1). A withheld shard costs nothing to bond against because nothing waits on an assigned prover: an unproven block delays only its proof; execution and the 30-s lock do not wait for it (ledger P9). The bond, slashed on a bad or late proof, remains in the external job market (5.4), where a customer does wait; its size and timeout are Open (O-5.6).
5.4 External job market
Designed. At launch external proving jobs are paid on the customer's chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum; the customer chain's own bond and slashing apply (design document, "The first six months"). When the job market settles on Igneum, which needs the proof bridge (phase 2 consensus proof, ledger P4, E7), every job fee paid in IGN splits:
| Share | Recipient |
|---|---|
| 90% | The provers who delivered the job |
| 10% | Burn |
The burn applies only to IGN-settled jobs (ledger P10). The bridge's trust model is decided (section 7.3, 3 October 2026): no bridge is official, no bridged stablecoin exists at genesis, and the proof bridge arrives with the consensus proof in phase two. IGN settlement switches on when that bridge exists; how the switch is activated is Open (O-5.2).
5.5 No development fund
Designed, decided 3 October 2026. There is no development fund and no protocol fee to any team, foundation or fund. Earlier drafts routed 5% of the priority fee and 5% of IGN-settled job fees to a fund contract that spent only on 60% miner signalling. Removed, because a switch that routes money to an address somebody controls is the first thing a critic points at, however it is gated. The team earns in the open, like anyone else: it runs provers in the job market (5.3, 5.4) and collects the developer share (5.2) on the contracts it deploys.
The 60% signalling mechanism stays as a general governance tool (5.8): a parameter that the genesis rules leave to miners is set by a proposal that passes at 60% of blue blocks over a window of 1,209,600 DAA s (two weeks), the BIP 9 model. A grant mechanism can be added the same way later if the community wants one; none is specified. Ledger E4 is closed by removal; O-5.4 no longer covers a fund contract.
5.6 No stake, no treasury
- No consensus rule reads a balance. No bond, deposit or stake affects block validity, vote weight, fork choice or finality. The external job bond of 5.4 is an execution-layer escrow, not a consensus weight; shards carry no bond at all (section 7.2).
- No unit of emission goes anywhere but the block producer (80%) and the proving pool (20%).
- The team holds no consensus key, no purse and no protocol fee (hostile review table, "A team that controls a treasury").
5.7 Upgrade signalling
Designed. Consensus rules change only through new code that activates when at least 90% of blue blocks in a signalling window carry the upgrade's signal. The window length, the activation delay after the window closes, and the proposal identifier format in the block (candidate: a version-bits field in the header version, Kaspa's field) are Open (O-5.3). The specification is updated to describe activated rules, not the other way round (section 0.4). Automatic changes (epoch programs, day keys, era draws, the sortition switch at 8,192 voters, dataset growth) are not upgrades and need no signal.
Emergency path: a soundness bug in the proof system cannot wait for a signalling window. The rule that contains it is execution-layer: a full node executes natively and rejects any proof whose claimed state root differs from its own execution, so a forged proof is a light-client problem and not a chain split (ledger P7). Writing the fix is human work; activating it is this section's signal.
5.8 Signalling encoding
Designed, Open (O-5.3). Each block carries a bitfield; bit b set means "this block signals for proposal b". Proposals are registered by a transaction naming the bit, the kind (parameter or upgrade), the threshold (60% for a parameter the genesis rules leave to miners, 90% for an upgrade) and the window start in DAA score. The count is over blue blocks with DAA score in the window. A proposal that fails may be re-registered.
5.9 Parameters in this section
| Parameter | Value | Label |
|---|---|---|
| Base fee burn | 100%, both dimensions | Designed |
| Priority fee split | 80 / 20 (producer and provers / developer) | Designed |
| External job split (IGN-settled) | 90 / 10 (provers / burn) | Designed |
| Parameter signalling threshold | 60% of blue blocks | Designed |
| Parameter signalling window | 1,209,600 DAA s | Designed (design document: "over two weeks") |
| Upgrade signalling threshold | 90% of blue blocks | Designed |
| Upgrade window, activation delay | not set | Open (O-5.3) |
| Shard assignment | sortition, 8 provers, 10-s window, no bond (section 7.2) | Designed (3 October 2026) |
| External job bond, claim timeout | not set | Open (O-5.6) |
| Proving-cost budget per block | from the phase 2 measurement | Target |
| Emission to any treasury | 0 | Designed |
| Protocol fee to any team, foundation or fund | 0 | Designed (3 October 2026) |