igneum/docs/spec/05-fees-and-economics.md

18 KiB

Igneum protocol specification, section 5: fees, splits, burns, signalling

Spec version 0.1, 3 October 2026. Status of this section: Designed (design document, "The token", "Finality rule, version 2: Fees", decisions table "What do I get for being early?"). Nothing here is implemented or measured, except section 5.10, which is Decided (5 October 2026) and carries a simulation. Emission itself is section 2.5.

Two rules frame everything: there is no stake anywhere in consensus, and the protocol carries no fee to any team, foundation or fund. Not one unit of emission or of fees goes to a treasury, a fund, a founder or a stake. The development fund that earlier drafts carried (5% of tips and 5% of job fees under 60% signalling) was removed on 3 October 2026 (section 5.5).

5.1 Base fee

Designed. Every transaction pays a base fee in both gas dimensions:

Dimension What it meters Who sets it
Execution gas EVM execution, Ethereum's rule Ethereum's EIP-1559-style base fee over the ordered sequence
Proving-cost gas Proving cycles the transaction will cost the provers A second base fee f_p, adjusted per chain block by the same EIP-1559 step as f_e: toward a target of B_p / 2 of proving gas used, denominator 8, never below the floor of section 5.11 (one definition, 5 October 2026, ledger P14; next_base_fee in igneum/exec/src/executor.rs, applied per chain block in service.rs). The unproven backlog does not move f_p; it halves B_p (design 4.3, the backlog rule), which raises f_p through the step. No smoothing over the difficulty window is implemented or specified: the two-dimension step is per chain block

The base fee in both dimensions is burned in full. A miner cannot stuff blocks with its own transactions for free; wash gas loses its whole base fee (ledger E3). The proving-cost budget per block is a consensus constant set from measured prover throughput (phase 2 gate: one shard on a 12 GB card in about 20 s, Target, unmeasured, ledger P1), so a transaction that is cheap to run and brutal to prove cannot stall the provers for everyone. How the node folds the proving-cost dimension into the quoted gas price so eth_estimateGas keeps working is fixed in section 7.1 (ledger P5, closed 3 October 2026).

5.2 Priority fee split

Designed. The priority fee (tip) of every executed transaction splits:

Share Recipient Rule
80% Block producer and provers The producer of the block in which the first copy executed (section 2.6) and the provers of that block, in the proportion the proving protocol defines (forward reference)
20% Developer Attributed per call frame by gas consumed, to the developer address registered for the called contract at deployment. A frame in an unregistered contract sends its share to the burn

No part of the tip is burned by rule; the burn is the base fee (5.1) and the unregistered developer share.

Per-call-frame attribution: a transaction that calls contract A, which calls B, which calls C, pays 20% of the tip in proportion to the gas each frame consumed, to A's, B's and C's registrations respectively. A frame's own gas excludes the gas of frames it called.

Factory rule: a contract deployed by another contract (CREATE or CREATE2 from a contract) inherits the deploying contract's registration unless it re-registers in the same transaction. A contract deployed from an externally owned account registers the address the deployment names, or none.

Self-dealing: a developer who also mines the including block collects 80% plus 20%, the whole tip, and still loses the whole base fee in both dimensions, so wash gas is a guaranteed loss; it can still inflate a "gas earned" figure on a leaderboard, so no explorer ranking should use raw developer share without a self-dealing filter (ledger E3; not a consensus rule).

5.3 Proving pool

Designed. The 20% emission share (section 2.5) and the provers' part of the 80% tip share are paid per block as a fixed amount for that block, divided among the block's shards by consensus proving cost, so a stuffed block earns no more than an honest one. Shards are not claimed first-come and carry no bond: each shard is assigned by sortition to 8 eligible provers for a 10-s exclusive window, then open to anyone, and the first valid proof included in a block is paid (section 7.2, decided 3 October 2026, ledger P8, C9). The parameters 8 and 10 s are set on the phase 4 devnet (O-5.1). A withheld shard costs nothing to bond against because nothing waits on an assigned prover: an unproven block delays only its proof; execution and the 30-s lock do not wait for it (ledger P9). The bond, slashed on a bad or late proof, remains in the external job market (5.4), where a customer does wait; its size and timeout are Open (O-5.6).

5.4 External job market

Designed. At launch external proving jobs are paid on the customer's chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum; the customer chain's own bond and slashing apply (design document, "The first six months"). When the job market settles on Igneum, which needs the proof bridge (phase 2 consensus proof, ledger P4, E7), every job fee paid in IGN splits:

Share Recipient
90% The provers who delivered the job
10% Burn

The burn applies only to IGN-settled jobs (ledger P10). The bridge's trust model is decided (section 7.3, 3 October 2026): no bridge is official, no bridged stablecoin exists at genesis, and the proof bridge arrives with the consensus proof in phase two. IGN settlement switches on when that bridge exists; how the switch is activated is Open (O-5.2).

5.5 No development fund

Designed, decided 3 October 2026. There is no development fund and no protocol fee to any team, foundation or fund. Earlier drafts routed 5% of the priority fee and 5% of IGN-settled job fees to a fund contract that spent only on 60% miner signalling. Removed, because a switch that routes money to an address somebody controls is the first thing a critic points at, however it is gated. The team earns in the open, like anyone else: it runs provers in the job market (5.3, 5.4) and collects the developer share (5.2) on the contracts it deploys.

The 60% signalling mechanism stays as a general governance tool (5.8): a parameter that the genesis rules leave to miners is set by a proposal that passes at 60% of blue blocks over a window of 1,209,600 DAA s (two weeks), the BIP 9 model. A grant mechanism can be added the same way later if the community wants one; none is specified. Ledger E4 is closed by removal; O-5.4 no longer covers a fund contract.

5.6 No stake, no treasury

  • No consensus rule reads a balance. No bond, deposit or stake affects block validity, vote weight, fork choice or finality. The external job bond of 5.4 is an execution-layer escrow, not a consensus weight; shards carry no bond at all (section 7.2).
  • No unit of emission goes anywhere but the block producer (80%) and the proving pool (20%).
  • The team holds no consensus key, no purse and no protocol fee (hostile review table, "A team that controls a treasury").

5.7 Upgrade signalling

Designed. Consensus rules change only through new code that activates when at least 90% of blue blocks in a signalling window carry the upgrade's signal. The window length, the activation delay after the window closes, and the proposal identifier format in the block (candidate: a version-bits field in the header version, Kaspa's field) are Open (O-5.3). The specification is updated to describe activated rules, not the other way round (section 0.4). Automatic changes (epoch programs, day keys, era draws, the sortition switch at 8,192 voters, dataset growth) are not upgrades and need no signal.

Emergency path: a soundness bug in the proof system cannot wait for a signalling window. The rule that contains it is execution-layer: a full node executes natively and rejects any proof whose claimed state root differs from its own execution, so a forged proof is a light-client problem and not a chain split (ledger P7). Writing the fix is human work; activating it is this section's signal.

5.8 Signalling encoding

Designed, Open (O-5.3). Each block carries a bitfield; bit b set means "this block signals for proposal b". Proposals are registered by a transaction naming the bit, the kind (parameter or upgrade), the threshold (60% for a parameter the genesis rules leave to miners, 90% for an upgrade) and the window start in DAA score. The count is over blue blocks with DAA score in the window. A proposal that fails may be re-registered.

5.9 Parameters in this section

Parameter Value Label
Base fee burn 100%, both dimensions Designed
Priority fee split 80 / 20 (producer and provers / developer) Designed
External job split (IGN-settled) 90 / 10 (provers / burn) Designed
Parameter signalling threshold 60% of blue blocks Designed
Parameter signalling window 1,209,600 DAA s Designed (design document: "over two weeks")
Upgrade signalling threshold 90% of blue blocks Designed
Upgrade window, activation delay not set Open (O-5.3)
Shard assignment sortition, 8 provers, 10-s window, no bond (section 7.2) Designed (3 October 2026)
External job bond, claim timeout not set Open (O-5.6)
Proving-cost budget per block B_p 120,000 pgas (section 5.10) Adopted (5 October 2026, as proposed on 4 October 2026; was Target)
Shard budget S_p 30,000 pgas (section 5.10) Adopted (5 October 2026, as proposed on 4 October 2026)
Base-fee floors f_e, f_p 100 gwei per gas, 10,000 gwei per pgas (section 5.10) Adopted (5 October 2026, as proposed on 4 October 2026)
pgas table version 1: intrinsic 300, modexp 10 + 1 per 10 bytes, other entries prototype (section 5.10) Adopted (5 October 2026, as proposed on 4 October 2026)
Emission to any treasury 0 Designed
Protocol fee to any team, foundation or fund 0 Designed (3 October 2026)
Tail emission 0; the 4,000,000,000 IGN cap of section 2.5 is absolute Decided (5 October 2026, section 5.10)
Tail-reward review trigger external proving revenue under 1/5 of the block subsidy over any 90-day window after year 5 puts the question to the miners' vote (5.7); the protocol never changes emission by itself Decided (5 October 2026, section 5.10.3)

5.10 Security budget after the subsidy

Decided 5 October 2026 by the owner: the 4,000,000,000 IGN hard cap of section 2.5 is absolute and there is no tail emission. The security budget after the subsidy fades is the proving market (external proof jobs, dollars-priced work settled in the token, 90% to the provers who delivered, section 5.4) plus fees (the 80% producer-and-prover share of the priority fee, section 5.2). Ledger E15; open item O-5.11, decided.

5.10.1 What the subsidy alone pays for

Measured by python3 sim/economy/security_budget.py (5 October 2026, default arguments; the floor is from docs/analysis/security-budget.md, 3 October 2026, section 6). The assumptions, every one an input and none a prediction:

Input Value
Emission section 2.5: 1,000,000,000 IGN a year of 365.25 days in years 1 and 2, minus the 30-day ramp in year 1 (about 37,000,000 IGN never minted), halving every 63,115,200 DAA s; 80% to miners, 20% to the proving pool
Price flat at USD 0.005, 0.02 and 0.10 per IGN for 14 years; and the base price USD 0.02 on a falling path (-30% a year) and a rising path (+30% a year)
Fees a priority-fee grid of 0, 0.01, 0.1 and 1 IGN a block at 1 block/s, 80% to miners and provers split 50/50; external demand 0 or USD 2,000 a day, 90% to provers; the base-fee burn reaches nobody and is not counted
Card 300 W at 124 MH/s (the RTX 5090 on the devnet, 4 October 2026); electricity USD 0.12 per kWh; USD 315.58 of power per card-year
Floor USD 1,000,000 a year to miners: the power of 3,169 such cards ("about 3,000"; 393 GH/s), the fleet at which one 1,000-card operator holds a third of the 30-day vote weight
Fleet the cards whose power the miners' subsidy pays at break-even; capital, rent and margin are zero, so the fleet is an upper bound
Attacker a 51% attacker matches that fleet for 24 h at the same electricity price, a lower bound on the attack; the 20-day figure is the two-thirds campaign of section 3 (20 days of 100% of hashrate)

The years at which the subsidy alone, with no tips and no external demand, pays miners less than the floor:

Flat price, USD per IGN First year under the floor Subsidy to miners that year, USD Cards that subsidy powers 51% attacker's electricity, USD a day 20-day campaign, USD
0.005 7 500,000 1,584 1,369 27,379
0.02 11 500,000 1,584 1,369 27,379
0.10 none within 14 years (the row shows year 14) 1,250,000 3,961 3,422 68,446

For scale, year 1 at USD 0.005: 3,852,000 to miners, 12,206 cards (1.51 TH/s), USD 10,546 of attacker electricity a day, USD 210,924 over 20 days. The crossing year is the same at every fee level in the grid: 1 IGN a block of tips is 12,623,040 IGN a year to miners, about a tenth of year-7 emission. The falling path crosses in year 5 at every fee level except the highest (1 IGN a block with launch demand), where it crosses in year 6; the rising path never within 14 years. Readers with another electricity price or card can re-run the script with --elec, --card-w and --card-mh; a 2x change in the floor moves the year by at most one halving.

5.10.2 The decision and the reasoning

The cap stays. Provers' income does not depend on emission: a prover is paid per job (90% of the job fee, 5.4) and per block from the tip share (5.2), and both scale with demand for proofs and for block space, not with the schedule. The 20% emission share is a launch subsidy for a standing prover population; when it fades, the proving market is what keeps the cards on, and a card that is on can hash. The subsidy to miners fades on the schedule every capped proof-of-work chain shares; here the years are measured and stated, and the same hardware has a second income that emission never paid. A tail reward is ruled out as a protocol default, not for ever: the trigger below says when the question is put to the miners, and only their vote can change the schedule.

5.10.3 Review trigger

REVIEW TRIGGER (rule). If external proving revenue is under one fifth of the block subsidy over any 90-day window (7,776,000 DAA s) after the end of year 5 (DAA score 157,788,000), the question of a tail reward goes to the miners' signalling vote. The protocol itself never changes emission without that vote.

  • External proving revenue: job fees settled in IGN under 5.4, counted at settlement over the window. Until jobs settle in IGN (O-5.2), it is what the payout contracts on customer chains received over the window, converted at the window's settlement rate and published with the reading. Block subsidy: E(t) of section 2.5 summed over the same window, in IGN.
  • The reading is made by people from chain data and published. The chain computes nothing and changes nothing.
  • The vote: a tail reward changes a consensus constant fixed at genesis, so it is an upgrade under 5.7 (90% of blue blocks over the window of O-5.3), not a 60% parameter. Anyone may register the proposal under 5.8 once the condition has held; a proposal that fails may be re-registered after the next qualifying window.
  • Nothing in this rule obliges the vote to pass. The cap is the default; a tail reward is a change miners may adopt, and the protocol never adopts it by itself.

5.11 Base-fee floors, the proving budget and the pgas table (Adopted 5 October 2026)

Proposed on 4 October 2026 and adopted by the owner on 5 October 2026, as proposed (the sign-off is recorded in docs/plans/release-0.3.6.md). The arithmetic is in docs/analysis/base-fee-floor.md; the values are implemented in the node fork (consensus/core/src/fees.rs, FeeParams::CALIBRATED_V1, carried by Params.fees per network and by the override file; merged into the fork's release-0.3.6). The testnet and the mainnet run them from genesis. The devnet and the simnet keep the prototype values (both base fees 1 gwei with a 1 gwei floor, B_p = B_e = 30,000,000, intrinsic 200, modexp 1,000 + 10 per byte; FeeParams::PROTOTYPE) until the fees_v1_activation_daa height switch, carried by the override file and the consensus digest, moves them: chain blocks at or above that DAA score meter with the adopted table, budgets and floors, and the first such block raises both base fees to the floors. Devnet switch: DAA score 210,000 (chosen 5 October 2026, about 19:50 UTC on 6 October at the measured 0.965 blocks/s; the rollout is docs/plans/fee-switch-devnet.md). The prover's guest carries both tables and the switch (5 October 2026), so one program serves on either side of it.

Parameter Adopted Basis
pgas unit 1 pgas = 1,000 reference SP1 cycles unchanged
Intrinsic pgas per transaction 300 measured upper bound: 1,400 to 1,600 cycles per prototype pgas on a plain-transfer shard (bench-log, 4 October)
modexp entry 10 + 1 per 10 input bytes measured: 9 cycles per prototype pgas on a modexp-heavy shard, the prototype entry about 100x its cost
Other opcode and precompile entries prototype shapes, table version 1 not yet measured
Shard budget S_p 30,000 pgas (30 M cycles) about 5.5 s compressed on one RTX 5090 (half the measured 60 M-cycle shard at 10.9 s, approximate); about 20 s on a 12 GB card (approximate)
Block proving budget B_p 120,000 pgas (4 x S_p) 400 transfers per block; a four-shard block proves in about 8 s on four RTX 5090s (approximate)
Execution base-fee floor f_e 100 gwei per gas a full block burns 3 IGN, 9.5% of the year-one subsidy; 259,200 IGN per day
Proving base-fee floor f_p 10,000 gwei per pgas 230x the proving electricity per pgas at an assumed $0.10 per IGN and $0.15 per kWh
Initial base fees the floors
Adjustment EIP-1559 toward half the limit, denominator 8, both dimensions unchanged
A plain transfer at the floor 21,000 x 100 gwei + 300 x 10,000 gwei = 0.0051 IGN under $0.01 for any token price up to $1.96 (assumption, not a forecast)

The floors and B_p are parameters the genesis rules leave to miners (5.5): they move by 60% signalling.