igneum/site/litepaper.html

997 lines
168 KiB
HTML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
<title>Igneum Litepaper: how the chain works</title>
<meta name="description" content="The Igneum litepaper. A GPU-secured network for Ethereum-compatible applications and verifiable computation. GPU mining, proven execution, GHOSTDAG ordering, miner-only finality, the 4 billion cap. No premine, no stake.">
<link rel="canonical" href="https://igneum.network/litepaper">
<meta name="theme-color" content="#0C0C0E">
<!-- share:start -->
<meta property="og:type" content="website">
<meta property="og:site_name" content="Igneum">
<meta property="og:title" content="The Igneum litepaper">
<meta property="og:description" content="The hourly GPU lottery, blocks proven by miners, miner-only finality. No premine, no stake.">
<meta property="og:url" content="https://igneum.network/litepaper">
<meta property="og:image" content="https://igneum.network/og/litepaper.png?v=4">
<meta property="og:image:type" content="image/png">
<meta property="og:image:width" content="1200">
<meta property="og:image:height" content="630">
<meta property="og:image:alt" content="Mined by GPUs. Proven by fire. igneum.network/litepaper">
<meta property="og:image" content="https://igneum.network/og/litepaper-square.png?v=4">
<meta property="og:image:type" content="image/png">
<meta property="og:image:width" content="1200">
<meta property="og:image:height" content="1200">
<meta property="og:image:alt" content="Mined by GPUs. Proven by fire. igneum.network/litepaper">
<meta name="twitter:card" content="summary_large_image">
<meta name="twitter:title" content="The Igneum litepaper">
<meta name="twitter:description" content="The hourly GPU lottery, blocks proven by miners, miner-only finality. No premine, no stake.">
<meta name="twitter:image" content="https://igneum.network/og/litepaper.png?v=4">
<meta name="twitter:image:alt" content="Mined by GPUs. Proven by fire. igneum.network/litepaper">
<!-- share:end -->
<link rel="icon" href="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 1024 1024'%3E%3Crect width='1024' height='1024' fill='%230C0C0E'/%3E%3Cg transform='translate(166.95 166.95) scale(6.901)'%3E%3Cpolygon points='50,4 74,34 67,58 80,54 61,96 39,96 20,54 33,58 26,34' fill='%23F2541B'/%3E%3Cpolygon points='50,42 59,58 50,82 41,58' fill='%230C0C0E'/%3E%3C/g%3E%3C/svg%3E" type="image/svg+xml">
<link rel="icon" href="/favicon.ico" sizes="48x48">
<link rel="icon" href="/favicon-32.png" type="image/png" sizes="32x32">
<link rel="icon" href="/icon-192.png" type="image/png" sizes="192x192">
<link rel="icon" href="/icon-512.png" type="image/png" sizes="512x512">
<link rel="apple-touch-icon" href="/apple-touch-icon.png" sizes="180x180">
<link rel="manifest" href="/site.webmanifest">
<link rel="preload" href="/fonts/unbounded-500.woff2" as="font" type="font/woff2" crossorigin>
<!-- head:start -->
<link rel="preload" href="/fonts/unbounded-900.woff2" as="font" type="font/woff2" crossorigin>
<link rel="preload" href="/fonts/plex-sans-400.woff2" as="font" type="font/woff2" crossorigin>
<meta name="color-scheme" content="dark light">
<link rel="stylesheet" href="/site.css">
<style>
/* Shared by every page: the head partial, injected by the build between the head markers. Edit the partial, not the page. */
/* Fonts, self-hosted (latin subsets, OFL): Unbounded 500/700/900, IBM Plex Sans 400/500/600, IBM Plex Mono 400/500. Fallbacks carry size and ascent overrides so the swap does not move the layout. The tokens, type and components are in /site.css (docs/plans/site-ui-3.md). */
@font-face{font-family:'Unbounded';font-style:normal;font-weight:500;font-display:swap;src:url(/fonts/unbounded-500.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'Unbounded';font-style:normal;font-weight:700;font-display:swap;src:url(/fonts/unbounded-700.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'Unbounded';font-style:normal;font-weight:900;font-display:swap;src:url(/fonts/unbounded-900.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'IBM Plex Sans';font-style:normal;font-weight:400;font-display:swap;src:url(/fonts/plex-sans-400.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'IBM Plex Sans';font-style:normal;font-weight:500;font-display:swap;src:url(/fonts/plex-sans-500.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'IBM Plex Sans';font-style:normal;font-weight:600;font-display:swap;src:url(/fonts/plex-sans-600.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'IBM Plex Mono';font-style:normal;font-weight:400;font-display:swap;src:url(/fonts/plex-mono-400.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'IBM Plex Mono';font-style:normal;font-weight:500;font-display:swap;src:url(/fonts/plex-mono-500.woff2) format('woff2');unicode-range:U+0000-00FF,U+0131,U+0152-0153,U+02BB-02BC,U+02C6,U+02DA,U+02DC,U+0304,U+0308,U+0329,U+2000-206F,U+20AC,U+2122,U+2191,U+2193,U+2212,U+2215,U+FEFF,U+FFFD}
@font-face{font-family:'Unbounded Fallback';src:local('Arial Black'),local('Arial-Black'),local('Impact');size-adjust:114%;ascent-override:87.5%;descent-override:21.5%;line-gap-override:0%}
@font-face{font-family:'Plex Sans Fallback';src:local('Arial'),local('Helvetica Neue'),local('Helvetica');size-adjust:100.5%;ascent-override:102%;descent-override:27.4%;line-gap-override:0%}
@font-face{font-family:'Plex Mono Fallback';src:local('Courier New'),local('Menlo');size-adjust:100%;ascent-override:102.5%;descent-override:27.5%;line-gap-override:0%}
</style>
<script>
/* theme before first paint: ?theme=light|dark for one view (the capture tool), else the stored choice under igneum-theme, else the system setting; ?motion=off marks the page data-motion=off so every .reveal is drawn at once (a headless render never scrolls) */
(function(){var t=null;try{t=new URLSearchParams(location.search).get("theme");}catch(e){}if(t!=="light"&&t!=="dark"){try{t=localStorage.getItem("igneum-theme");}catch(e){t=null;}}if(t!=="light"&&t!=="dark")t=window.matchMedia&&window.matchMedia("(prefers-color-scheme: light)").matches?"light":"dark";document.documentElement.setAttribute("data-theme",t);try{if(new URLSearchParams(location.search).get("motion")==="off")document.documentElement.setAttribute("data-motion","off");}catch(e){}})();
</script>
<!-- head:end -->
<style>
/* litepaper block (docs/plans/site-ui-3.md section 4); tokens, type and components are in /site.css */
[id]{scroll-margin-top:var(--lp-off,84px)}
.cover{padding:65px 0 45px;display:flex;flex-wrap:wrap;gap:40px;align-items:flex-end;justify-content:space-between}
.cover h1{margin:0 0 24px;font-size:clamp(36px,4.2vw,56px);max-width:22ch}
.cover .tag{font-size:18px;line-height:1.65;color:var(--ink-2);max-width:67ch}
.meta{display:flex;flex-direction:column;gap:6px;font:10px/1.8 var(--mono);color:var(--ash);text-align:right}
.meta b{color:var(--bone);font-weight:500}
.layout{display:grid;grid-template-columns:minmax(0,1fr);gap:32px;padding:0 0 100px}
@media (min-width:960px){.layout{grid-template-columns:230px minmax(0,1fr);gap:55px}}
.toc{align-self:start}
@media (min-width:960px){.toc{position:sticky;top:112px;max-height:calc(100vh - 145px);overflow:auto;border-right:1px solid var(--line);padding-right:20px;scrollbar-width:thin}}
.toc ol{list-style:none;margin:0;padding:0;display:flex;flex-direction:column;gap:2px;counter-reset:s}
.toc li a{display:flex;gap:10px;padding:8px 10px;border-left:2px solid transparent;color:var(--ash);font-size:12px;counter-increment:s;line-height:1.35}
.toc li a::before{content:counter(s,decimal-leading-zero);font-family:var(--mono);font-size:11px;color:var(--ash);min-width:22px;padding-top:1px}
.toc li a:hover{background:var(--ember-tint);color:var(--ember);border-left-color:var(--ember)}
.toc li a.active{background:var(--ember-tint);color:var(--ember);border-left-color:var(--ember);font-weight:500;box-shadow:none}
.toc li a.active::before{color:var(--ember)}
.toc .dl{margin-top:18px;padding-top:18px;border-top:1px solid var(--line);font-size:13px;color:var(--ash)}
.toc .mode{margin-top:14px;display:flex;border:1px solid var(--line);border-radius:var(--r-pill);overflow:hidden}
.toc .mode button{flex:1;min-height:36px;border:0;background:transparent;color:var(--ash);font:500 12px/1 var(--f-mono);cursor:pointer}
.toc .mode button.on{background:var(--graphite);color:var(--bone)}
article{max-width:810px}
article section{padding-bottom:42px;margin-bottom:42px;border-bottom:1px solid var(--line)}
article section:first-of-type{border-top:0;padding-top:0}
article h2{font-size:27px;margin:0 0 22px}article section>h2::before{content:"Section " counter(sec,decimal-leading-zero);display:block;font:11px var(--mono);color:var(--ember);margin-bottom:13px;letter-spacing:.04em}article{counter-reset:sec}article section{counter-increment:sec}
article h3{font-size:16px;margin:26px 0 13px;font-weight:700}
article .lead{margin-bottom:var(--s-4)}
article ul,article ol{margin:0 0 var(--s-4);padding-left:22px}
article li{margin:9px 0;color:var(--ink-2);font-size:15px}
article p{color:var(--ink-2);font-size:16px;line-height:1.85}
article strong{color:var(--bone);font-weight:600}
.pull{margin:25px 0;padding:18px 24px;border-left:2px solid var(--ember);background:var(--row);border-radius:0 10px 10px 0;font:500 19px/1.45 var(--sans);color:var(--bone)}
.tbl{margin:var(--s-4) 0 var(--s-5)}
table{min-width:560px}
.figure{margin:var(--s-5) 0;padding:var(--s-5);background:var(--graphite);border:1px solid var(--line);border-radius:var(--r-card);overflow-x:auto}
.figure svg{display:block;width:100%;height:auto;max-width:100%}
.figure .cap{margin-top:var(--s-3);font:400 var(--t-sm)/1.5 var(--f-mono);color:var(--ash)}
.stats{display:grid;grid-template-columns:repeat(2,minmax(0,1fr));gap:var(--s-3);margin:var(--s-2) 0 var(--s-5)}
@media (min-width:700px){.stats{grid-template-columns:repeat(4,minmax(0,1fr))}}
.stat{padding:var(--s-4);background:var(--row);border:1px solid var(--line);border-radius:var(--r-row);min-width:0}
.stat .v{font:700 var(--t-num)/1 var(--f-display);color:var(--bone);letter-spacing:-.02em}
.stat .k{margin-top:var(--s-2);font:400 var(--t-sm)/1.4 var(--f-mono);color:var(--ash);text-wrap:balance}
pre{margin:0 0 var(--s-4)}
.foot{margin-top:0}
article section{display:none}
article section.active{display:block}
body.all article section{display:block;border-top:0}
body.all article section:first-of-type{border-top:0;padding-top:0}
article h2:focus,article h3:focus{outline:none}
article h2:focus-visible,article h3:focus-visible{outline:2px solid var(--ember);outline-offset:6px;border-radius:4px}
.pager{display:flex;justify-content:space-between;gap:var(--s-3);margin-top:var(--s-6);padding-top:var(--s-5);border-top:1px solid var(--line)}
.pager a{display:inline-flex;align-items:center;gap:8px;min-height:44px;padding:10px 16px;border:1px solid var(--line);border-radius:var(--r-btn);color:var(--bone);font-size:14px;max-width:48%}
.pager a:hover{text-decoration:none;border-color:var(--line-2);background:var(--hover)}
.pager a span{color:var(--ash);font:500 var(--t-xs)/1.4 var(--f-mono);letter-spacing:.12em;text-transform:uppercase}
.pager a.next{margin-left:auto;text-align:right}
body.all .pager{display:none}
.src{margin:calc(-1 * var(--s-2)) 0 var(--s-5);font:400 13px/1.5 var(--f-mono);color:var(--ash)}
.src b{font-weight:500;color:var(--ink-2)}
@media (max-width:600px){.pager{flex-direction:column}.pager a{max-width:none;justify-content:space-between}.pager a.next{margin-left:0}}
@media (max-width:959px){
.toc{position:sticky;top:var(--nav-h);z-index:5;background:var(--obsidian);margin-inline:calc(-1 * var(--gutter));padding:8px var(--gutter);border-bottom:1px solid var(--line)}
.toc ol{flex-direction:row;overflow-x:auto;gap:6px;scrollbar-width:none;-webkit-overflow-scrolling:touch;padding-bottom:2px;scroll-padding-inline:var(--gutter)}
.toc ol::-webkit-scrollbar{display:none}
.toc li a{white-space:nowrap;border:1px solid var(--line);border-radius:999px;padding:7px 12px;font-size:13px;gap:6px}
.toc li a.active{box-shadow:none;border-color:var(--ember)}
.toc li a::before{min-width:0}
.toc .dl{display:none}
.toc .mode{margin-top:6px}
.toc .mode button{min-height:32px}
}
@media print{article section{display:block!important;border-top:1px solid #bbb;padding-top:18pt}.toc,.pager,.cover .meta span:last-child{display:none!important}.layout{display:block}article{max-width:none}table{min-width:0}}
</style>
</head>
<body>
<!-- nav:start -->
<a class="skip" href="#main">Skip to content</a>
<nav class="nav" aria-label="Main" data-nav-version="5">
<div class="container nav-row">
<a href="/" class="logo" aria-label="Igneum home">
<svg class="brand-mark" viewBox="0 0 1024 1024" aria-hidden="true"><rect width="1024" height="1024" rx="160" fill="#0C0C0E"></rect><g transform="translate(166.95 166.95) scale(6.901)"><polygon points="50,4 74,34 67,58 80,54 61,96 39,96 20,54 33,58 26,34" fill="#F2541B"></polygon><polygon points="50,42 59,58 50,82 41,58" fill="#0C0C0E"></polygon></g></svg>
<span class="word">IGNEUM</span>
</a>
<span class="devnet" id="nav-devnet" title="igneum-devnet-4, the Igneum 2.0 devnet, chain id 4465. Coins have no value. The chain may reset."><span class="dot off" id="foot-dot"></span><span id="foot-state" data-devnet-state="live">Devnet live</span></span>
<div class="nav-groups" id="nav-groups" role="list">
<div class="nav-group" role="listitem"><button type="button" class="group-btn" id="nav-btn-mine" data-group="mine" aria-expanded="false" aria-controls="nav-panel-mine" aria-haspopup="true">Mine<svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><path d="m7 10 5 5 5-5"/></svg></button></div>
<div class="nav-group" role="listitem"><button type="button" class="group-btn" id="nav-btn-network" data-group="network" aria-expanded="false" aria-controls="nav-panel-network" aria-haspopup="true">Network<svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><path d="m7 10 5 5 5-5"/></svg></button></div>
<div class="nav-group" role="listitem"><button type="button" class="group-btn" id="nav-btn-learn" data-group="learn" data-active aria-expanded="false" aria-controls="nav-panel-learn" aria-haspopup="true">Learn<svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><path d="m7 10 5 5 5-5"/></svg></button></div>
<div class="nav-group" role="listitem"><button type="button" class="group-btn" id="nav-btn-build" data-group="build" aria-expanded="false" aria-controls="nav-panel-build" aria-haspopup="true">Build<svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><path d="m7 10 5 5 5-5"/></svg></button></div>
</div>
<div class="nav-controls">
<button class="btn icon-btn" type="button" data-theme-toggle aria-label="Switch to light theme"><svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><circle cx="12" cy="12" r="4"/><path d="M12 2v2m0 16v2M2 12h2m16 0h2M5 5l1 1m12 12 1 1M5 19l1-1M18 6l1-1"/></svg></button>
<a href="/download" class="btn primary small cta" data-nav="download">Download</a>
<button class="burger" id="nav-burger" type="button" aria-expanded="false" aria-controls="nav-sheet" aria-label="Open the menu" aria-haspopup="true"><svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><path class="bars" d="M4 6h16M4 12h16M4 18h16"/><path class="cross" d="m6 6 12 12M6 18 18 6"/></svg></button>
</div>
</div>
<div class="panels" id="nav-panels">
<div class="panel-wrap container">
<div class="nav-panel" id="nav-panel-mine" data-group="mine" role="region" aria-labelledby="nav-btn-mine" hidden>
<div class="panel-list">
<a href="/miner" data-nav="miner"><b>Ember, the miner</b><span>One click installs the node, the miner and the prover.</span></a>
<a href="/download" data-nav="download"><b>Download</b><span>Windows, macOS, Linux and HiveOS.</span></a>
<a href="/app" data-nav="app"><b>The app</b><span>What you see while the card mines.</span></a>
<a href="/wallet" data-nav="wallet"><b>The wallet</b><span>Your coins. Final means final.</span></a>
<a href="/miners" data-nav="miners"><b>GPU bench table</b><span>Measured rates, card by card.</span></a>
<a href="/dev-fee" data-nav="dev-fee"><b>The dev fee</b><span>The optional one, in full view, off with one flag.</span></a>
<a href="/metamask" data-nav="metamask"><b>Add to MetaMask</b><span>Igneum as a network in your wallet.</span></a>
</div>
</div>
<div class="nav-panel" id="nav-panel-network" data-group="network" role="region" aria-labelledby="nav-btn-network" hidden>
<div class="panel-list">
<a href="/live" data-nav="live"><b>Live devnet</b><span>The chain as it grows, one lane per miner.</span></a>
<a href="/explorer" data-nav="explorer"><b>Explorer</b><span>Look a block or an address up.</span></a>
<a href="/evidence" data-nav="evidence"><b>Evidence</b><span>Every claim and how far it is tested.</span></a>
<a href="/light" data-nav="light"><b>Light wallet</b><span>A balance your browser proves, trusting no node.</span></a>
<a href="/receipt" data-nav="receipt"><b>Payment receipt</b><span>A receipt any third party re-verifies offline.</span></a>
<a href="/oracle" data-nav="oracle"><b>State oracle on Sepolia</b><span>Balances on the devnet, read from another chain.</span></a>
</div>
</div>
<div class="nav-panel" id="nav-panel-learn" data-group="learn" role="region" aria-labelledby="nav-btn-learn" hidden>
<div class="panel-list">
<a href="/litepaper" data-nav="litepaper" aria-current="page"><b>Litepaper</b><span>The design, as published.</span></a>
<a href="/income" data-nav="income"><b>Income</b><span>What your card would mine, from the live network.</span></a>
<a href="/economics" data-nav="economics"><b>Economics</b><span>The emission, the split and the fees, each with its line in the node.</span></a><a href="/scorecard" data-nav="scorecard"><b>Scorecard</b><span>The twelve acceptance gates, their evidence and where each stands.</span></a>
<a href="/ledger" data-nav="ledger"><b>Ledger</b><span>Every criticism, answered or conceded.</span></a>
<a href="/claims" data-nav="claims"><b>What Igneum does not claim</b><span>The limits, stated first.</span></a>
<a href="/randomx" data-nav="randomx"><b>Igneum vs RandomX</b><span>What was kept and what was rebuilt for GPUs.</span></a>
<a href="/provenance" data-nav="provenance"><b>Built on the shoulders</b><span>Every borrowed part, credited.</span></a>
</div>
</div>
<div class="nav-panel" id="nav-panel-build" data-group="build" role="region" aria-labelledby="nav-btn-build" hidden>
<div class="panel-list">
<a href="/build" data-nav="build"><b>Build on Igneum</b><span>Chain ids, RPC, a contract in five minutes.</span></a>
<a href="/faucet" data-nav="faucet"><b>Devnet faucet</b><span>10 IGN of devnet coin, once a day.</span></a>
<a href="/swap" data-nav="swap"><b>Swap</b><span>Test tokens on the devnet; every swap is a proven block.</span></a>
<a href="/grants" data-nav="grants"><b>Grants</b><span>Tooling, apps, infrastructure, research.</span></a>
<a href="/compatibility" data-nav="compatibility"><b>Compatibility</b><span>Every row a test run against the devnet.</span></a>
</div>
</div>
</div>
</div>
<div class="nav-sheet" id="nav-sheet" role="dialog" aria-modal="true" aria-label="Menu" hidden>
<div class="sheet-scroll">
<div class="sheet-group"><div class="sheet-head">Mine</div>
<a href="/miner" data-nav="miner"><b>Ember, the miner</b><span>One click installs the node, the miner and the prover.</span></a>
<a href="/download" data-nav="download"><b>Download</b><span>Windows, macOS, Linux and HiveOS.</span></a>
<a href="/app" data-nav="app"><b>The app</b><span>What you see while the card mines.</span></a>
<a href="/wallet" data-nav="wallet"><b>The wallet</b><span>Your coins. Final means final.</span></a>
<a href="/miners" data-nav="miners"><b>GPU bench table</b><span>Measured rates, card by card.</span></a>
<a href="/dev-fee" data-nav="dev-fee"><b>The dev fee</b><span>The optional one, in full view, off with one flag.</span></a>
<a href="/metamask" data-nav="metamask"><b>Add to MetaMask</b><span>Igneum as a network in your wallet.</span></a>
</div>
<div class="sheet-group"><div class="sheet-head">Network</div>
<a href="/live" data-nav="live"><b>Live devnet</b><span>The chain as it grows, one lane per miner.</span></a>
<a href="/explorer" data-nav="explorer"><b>Explorer</b><span>Look a block or an address up.</span></a>
<a href="/evidence" data-nav="evidence"><b>Evidence</b><span>Every claim and how far it is tested.</span></a>
<a href="/light" data-nav="light"><b>Light wallet</b><span>A balance your browser proves, trusting no node.</span></a>
<a href="/receipt" data-nav="receipt"><b>Payment receipt</b><span>A receipt any third party re-verifies offline.</span></a>
<a href="/oracle" data-nav="oracle"><b>State oracle on Sepolia</b><span>Balances on the devnet, read from another chain.</span></a>
</div>
<div class="sheet-group"><div class="sheet-head">Learn</div>
<a href="/litepaper" data-nav="litepaper" aria-current="page"><b>Litepaper</b><span>The design, as published.</span></a>
<a href="/income" data-nav="income"><b>Income</b><span>What your card would mine, from the live network.</span></a>
<a href="/economics" data-nav="economics"><b>Economics</b><span>The emission, the split and the fees, each with its line in the node.</span></a><a href="/scorecard" data-nav="scorecard"><b>Scorecard</b><span>The twelve acceptance gates, their evidence and where each stands.</span></a>
<a href="/ledger" data-nav="ledger"><b>Ledger</b><span>Every criticism, answered or conceded.</span></a>
<a href="/claims" data-nav="claims"><b>What Igneum does not claim</b><span>The limits, stated first.</span></a>
<a href="/randomx" data-nav="randomx"><b>Igneum vs RandomX</b><span>What was kept and what was rebuilt for GPUs.</span></a>
<a href="/provenance" data-nav="provenance"><b>Built on the shoulders</b><span>Every borrowed part, credited.</span></a>
</div>
<div class="sheet-group"><div class="sheet-head">Build</div>
<a href="/build" data-nav="build"><b>Build on Igneum</b><span>Chain ids, RPC, a contract in five minutes.</span></a>
<a href="/faucet" data-nav="faucet"><b>Devnet faucet</b><span>10 IGN of devnet coin, once a day.</span></a>
<a href="/swap" data-nav="swap"><b>Swap</b><span>Test tokens on the devnet; every swap is a proven block.</span></a>
<a href="/grants" data-nav="grants"><b>Grants</b><span>Tooling, apps, infrastructure, research.</span></a>
<a href="/compatibility" data-nav="compatibility"><b>Compatibility</b><span>Every row a test run against the devnet.</span></a>
</div>
<div class="sheet-foot">
<a href="/download" class="btn primary big" data-nav="download">Download</a>
<div class="sheet-social"><a href="https://discord.gg/igneum" target="_blank" rel="noopener">Discord</a><a href="https://git.igneum.network/igneum-network/spec" target="_blank" rel="noopener">Source</a><a href="https://www.reddit.com/user/Igneum_network/" target="_blank" rel="noopener">Reddit</a></div>
</div>
</div>
</div>
</nav>
<script>
(function(){
// the slim bar (site-ui-5, 7 Oct 2026): three group buttons open one panel each; the burger opens the sheet on phones.
// Keyboard: Enter or Space opens a group, Escape closes it and returns focus to its button, arrows move between the
// group buttons, Tab walks the open panel's links, a click outside closes. The theme toggle flips data-theme and stores it.
var n=document.querySelector('.nav');if(!n)return;
var btns=[].slice.call(n.querySelectorAll('.group-btn')),panels=[].slice.call(n.querySelectorAll('.nav-panel')),wrap=n.querySelector('.panels');
var burger=document.getElementById('nav-burger'),sheet=document.getElementById('nav-sheet');
function panelOf(g){return panels.filter(function(p){return p.getAttribute('data-group')===g;})[0];}
function closeAll(focusBack){var was=null;btns.forEach(function(b){if(b.getAttribute('aria-expanded')==='true')was=b;b.setAttribute('aria-expanded','false');});panels.forEach(function(p){p.hidden=true;});n.classList.remove('panel-open');if(focusBack&&was)was.focus();}
function open(g){closeAll(false);var b=btns.filter(function(x){return x.getAttribute('data-group')===g;})[0],p=panelOf(g);if(!b||!p)return;b.setAttribute('aria-expanded','true');p.hidden=false;n.classList.add('panel-open');anchor(b,p);}
// the panel sits under its button; a panel that would run past the container's right edge aligns its right edge to the button's right edge instead (never past the viewport)
function anchor(b,p){var pw=n.querySelector('.panel-wrap');if(!pw)return;var cr=pw.getBoundingClientRect(),br=b.getBoundingClientRect(),w=p.offsetWidth,left=br.left-cr.left;if(left+w>cr.width)left=(br.right-cr.left)-w;if(left<0)left=0;p.style.setProperty('--panel-left',Math.round(left)+'px');}
window.addEventListener('resize',function(){var o=btns.filter(function(x){return x.getAttribute('aria-expanded')==='true';})[0];if(o)anchor(o,panelOf(o.getAttribute('data-group')));}); btns.forEach(function(b,i){
b.addEventListener('click',function(){var on=b.getAttribute('aria-expanded')==='true';if(on)closeAll(false);else open(b.getAttribute('data-group'));});
b.addEventListener('keydown',function(e){
var k=e.key;
if(k==='ArrowRight'||k==='ArrowLeft'){e.preventDefault();var j=(i+(k==='ArrowRight'?1:btns.length-1))%btns.length;btns[j].focus();if(n.classList.contains('panel-open'))open(btns[j].getAttribute('data-group'));}
else if(k==='ArrowDown'){e.preventDefault();open(b.getAttribute('data-group'));var f=panelOf(b.getAttribute('data-group')).querySelector('a');if(f)f.focus();}
else if(k==='Escape'){closeAll(true);}
});
});
if(wrap)wrap.addEventListener('keydown',function(e){if(e.key==='Escape'){e.stopPropagation();closeAll(true);}});
document.addEventListener('click',function(e){if(!n.classList.contains('panel-open'))return;if(e.target.closest('.group-btn')||e.target.closest('.nav-panel'))return;closeAll(false);});
document.addEventListener('focusin',function(e){if(!n.classList.contains('panel-open'))return;if(n.contains(e.target))return;closeAll(false);});
document.addEventListener('keydown',function(e){if(e.key==='Escape'&&n.classList.contains('panel-open'))closeAll(true);});
// the sheet on phones
function setSheet(o){if(!burger||!sheet)return;n.classList.toggle('open',o);sheet.hidden=!o;burger.setAttribute('aria-expanded',o?'true':'false');burger.setAttribute('aria-label',o?'Close the menu':'Open the menu');document.documentElement.classList.toggle('nav-locked',o);if(o){var f=sheet.querySelector('a');if(f)f.focus();}}
if(burger&&sheet){
burger.addEventListener('click',function(){setSheet(!n.classList.contains('open'));});
sheet.addEventListener('click',function(e){if(e.target.closest('a'))setSheet(false);});
sheet.addEventListener('keydown',function(e){
if(e.key==='Escape'){setSheet(false);burger.focus();return;}
if(e.key!=='Tab')return;var f=sheet.querySelectorAll('a,button');if(!f.length)return;var first=f[0],last=f[f.length-1];
if(e.shiftKey&&document.activeElement===first){e.preventDefault();burger.focus();}else if(!e.shiftKey&&document.activeElement===last){e.preventDefault();burger.focus();}
});
burger.addEventListener('keydown',function(e){if(e.key==='Tab'&&!e.shiftKey&&n.classList.contains('open')){e.preventDefault();var f=sheet.querySelector('a');if(f)f.focus();}});
var mq=window.matchMedia('(min-width:861px)');if(mq.addEventListener)mq.addEventListener('change',function(){setSheet(false);});
}
// the theme toggle
var t=n.querySelector('[data-theme-toggle]');
function paintToggle(){var dark=document.documentElement.getAttribute('data-theme')!=='light';t.setAttribute('aria-label',dark?'Switch to light theme':'Switch to dark theme');t.innerHTML=dark?'<svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><circle cx="12" cy="12" r="4"/><path d="M12 2v2m0 16v2M2 12h2m16 0h2M5 5l1 1m12 12 1 1M5 19l1-1M18 6l1-1"/></svg>':'<svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><path d="M20.7 13.3A8.5 8.5 0 0 1 10.7 3.3 8.5 8.5 0 1 0 20.7 13.3Z"/></svg>';}
if(t){t.addEventListener('click',function(){var v=document.documentElement.getAttribute('data-theme')==='light'?'dark':'light';document.documentElement.setAttribute('data-theme',v);try{localStorage.setItem('igneum-theme',v);}catch(e){}document.dispatchEvent(new CustomEvent('igneum-theme'));});paintToggle();document.addEventListener('igneum-theme',paintToggle);}
})();
</script>
<!-- nav:end -->
<main id="main" class="wrap">
<header class="cover">
<div>
<div class="breadcrumb"><a href="/">Igneum</a><span>/</span><span>The litepaper</span></div>
<div class="eyebrow"><span class="line"></span>The litepaper · Igneum 2.0</div>
<h1>Mined by GPUs.<br>Proven by fire.</h1>
<div class="tag">A GPU-secured network for Ethereum-compatible applications and verifiable computation.</div>
</div>
<div class="meta">
<span>Published <b>3 October 2026</b> · updated <b>8 October 2026</b></span>
<span>Coin <b>IGN</b> · cap <b>4,000,000,000</b></span>
<span>Status <b>The Igneum 2.0 devnet is live</b></span>
<span>Method <b>one founder with AI systems</b> · external review before gate 3</span>
<span>This is not an offer to sell anything</span>
</div>
</header>
<div class="layout">
<nav class="toc" aria-label="Contents">
<div class="eyebrow" style="margin-bottom:17px;font-size:10px">Contents</div>
<ol>
<li><a href="#abstract">Abstract</a></li>
<li><a href="#firsts">Precedents, and what Igneum adds</a></li>
<li><a href="#problem">The problem</a></li>
<li><a href="#glance">Igneum at a glance</a></li>
<li><a href="#mining">Mining</a></li>
<li><a href="#randomx">vs RandomX</a></li>
<li><a href="#proving">Proving</a></li>
<li><a href="#finality">Speed and finality</a></li>
<li><a href="#building">Building on Igneum</a></li>
<li><a href="#economics">Economics</a></li>
<li><a href="#miners">For miners</a></li>
<li><a href="#ember">Ember, the miner</a></li>
<li><a href="#wallet">The wallet</a></li>
<li><a href="#governance">Governance</a></li>
<li><a href="#roadmap">Roadmap</a></li>
<li><a href="#miners-ask">Questions miners ask</a></li>
<li><a href="#builders-ask">Questions builders ask</a></li>
<li><a href="#shoulders">Built on the shoulders</a></li>
<li><a href="#limits">What Igneum does not claim</a></li>
</ol>
<div class="mode" role="group" aria-label="Reading mode"><button type="button" id="m-all" class="on" aria-pressed="true">Whole paper</button><button type="button" id="m-tabs" aria-pressed="false">One section at a time</button></div>
<div class="dl">Latin igneum: fiery. A cupel is the vessel in which metal is proven by fire.</div>
</nav>
<article>
<section id="abstract">
<h2>Abstract</h2>
<p class="lead">A GPU-secured network for Ethereum-compatible applications and verifiable computation. Igneum is a proof-of-work chain built for graphics cards. AMD, Apple and NVIDIA cards mine; NVIDIA cards also prove its blocks with zero-knowledge proofs. Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling estimates a 1.5x to 3.1x energy-efficiency advantage for the specialised designs assessed as complete machines against the GPU tier, from a board on commodity DRAM at 1.5x to an SRAM-store die at 3.1x (1.5x to 2.3x on the GPU's own node). The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment. <a href="#chip-model">The chip model</a>: every number labelled measured, modelled or claimed, the harness and the scoring rules beside it.</p>
<p>It runs the Ethereum virtual machine through revm, so contracts built for Ethereum deploy with familiar tools; the differences (block context, randomness, two-dimensional fees) are documented. Transactions are included in about one second, proven within about a minute at launch, and locked by miners within about two (designed targets). There is no premine, no pre-sale, no treasury taken from emission, no stake anywhere in consensus, and no dependence on any other chain. Mining is built to stay open to anyone with a GPU. The argument rests on the scoring rule's result against placed adversary designs and on the economics, reported separately as energy advantage, economic advantage and response capability. The hourly program is an optional improvement, not the defence. Writing new code, including an emergency fix to the proof system, is the one thing that takes a person, and it activates only on miner signalling.</p>
<div class="stats">
<div class="stat"><div class="v">1 / s</div><div class="k">blocks, rising to 10 (designed)</div></div>
<div class="stat"><div class="v">~60 s</div><div class="k">to a proof at launch (designed)</div></div>
<div class="stat"><div class="v">0</div><div class="k">premine or stake</div></div>
<div class="stat"><div class="v">100%</div><div class="k">to miners and provers</div></div>
</div>
</section>
<section id="firsts">
<h2>Precedents, and what Igneum adds</h2>
<p>Every piece of Igneum has a precedent somewhere. We know of no chain that combines them. The table names the closest precedent for each piece, what Igneum adds, and how far each piece has got. It will be corrected when shown wrong.</p>
<div class="tbl"><table>
<thead><tr><th>Piece</th><th>Closest precedent</th><th>What Igneum adds</th><th>State, 8 Oct 2026</th></tr></thead>
<tbody>
<tr><td>A mining program that regenerates itself, for GPUs</td><td>RandomX on Monero since 2019, for CPUs, a program per hash; one chip shipped against it, Bitmain’s Antminer X5 (September 2023), a board of RISC-V chips at 1.46x per joule over a desktop CPU, on silicon believed mining privately from about 2021; the X9 was withdrawn in May 2026 with zero units; RandomX v2 was released on 25 March 2026 with its activation pending. ProgPoW, as KAWPOW on Ravencoin since 2020, changes the maths inside a fixed program shape every few blocks on GPUs (approximate)</td><td>A whole kernel per hour compiled to native code, a daily dataset from a 256 MB cache, a verifiable delay before the seed, era draws from a genesis reserve</td><td>Measured: hourly program swaps on Apple, NVIDIA and AMD cards, 4 October 2026</td></tr>
<tr><td>The mining card does paid, useful, verifiable work</td><td>Primecoin's prime chains in 2013 were not useful. Aleo ran proving as consensus and the fastest prover won (both approximate)</td><td>Proving kept apart from the lottery; shards assigned by sortition, not by speed</td><td>Implemented: proving v0 and v1 on the devnet from block zero, on NVIDIA cards. The job market for other chains is Designed</td></tr>
<tr><td>A proof-of-work chain where every block is proven</td><td>Proven-execution EVM chains run as rollups on proof-of-stake Ethereum. Conflux has run GPU-mined EVM apps on a DAG since 2020, without proofs (approximate)</td><td>Proven state on a proof-of-work base layer, produced by the miners themselves</td><td>Implemented: shards proven and paid on the devnet; proof verification enforced in consensus from block zero on the Igneum 2.0 devnet (running since 17:14 UK on 8 October 2026)</td></tr>
<tr><td>Finality held by miners and not moved by hour-long rentals</td><td>Decred votes with stake. Horizen penalises hidden chains. Kaspa limits merge depth (approximate)</td><td>Vote weight is 30 days of blocks per key. Hashrate that appeared today has no vote</td><td>Implemented: rule v3 live on the devnet from block zero. External review is owed at gate 3</td></tr>
<tr><td>100% of emission to the people running the hardware</td><td>Kaspa's fair launch. Zcash and Decred fund developers from emission (approximate)</td><td>No fee to any team, foundation or fund in the protocol. The miner software's optional 1% dev fee is the one payment to the project, off with one flag</td><td>Implemented in consensus: the 80/20 coinbase on the devnet</td></tr>
<tr><td>A chain your browser verifies by itself</td><td>Light clients trust a committee, as Ethereum's trust a sync committee (approximate)</td><td>At launch, one execution proof plus a certificate the client is given. The consensus proof that makes the checkpoint self-verifying is phase two</td><td>Designed. The home page's card verifies a devnet certificate in the browser today, with the voter list taken from a node</td></tr>
</tbody>
</table></div>
<p class="src"><b>Sources:</b> the engineering log for every Measured and Implemented cell; the provenance table in the repository for what was taken from each project and under which licence. Claims about other chains are from memory until cited from their repositories and are marked approximate.</p>
<div class="pull">GPU mining lost its largest home in 2022. Igneum is built to make it hard to take away: by a chip, by a merge to proof of stake, by a rental attack, or by a foundation.</div>
</section>
<section id="problem">
<h2>The problem</h2>
<p>Three things are wrong at once, and Igneum is built where they meet.</p>
<h3>GPU mining has no home</h3>
<p>Ethereum left proof of work in 2022 and stranded the largest fleet of general-purpose compute ever assembled. Since then the GPU chains have gone two ways. Chips arrived, as on Kaspa, whose hash was designed to welcome them. Or the chain stayed small: Ergo, Ravencoin and Conflux still mine on GPUs at a fraction of the 2022 fleet (approximate). Miners burn electricity on a lottery and are paid in inflation. When the price falls they switch off, and the chain's security goes with them.</p>
<h3>Proving is centralised</h3>
<p>Rollups, bridges and soon Ethereum itself need zero-knowledge proofs of every batch and every block. Today those proofs come from a few private GPU clusters run by the rollup teams or by a handful of proving companies. The work is a commodity, a proof is correct or it is not, and the cheapest correct proof should win. It does not, because the people with the cheapest GPUs are not in the market.</p>
<h3>Small proof-of-work chains get attacked</h3>
<p>When rental markets can hire more hashrate than a chain has for an hour, double-spends against exchanges are cheap. Ethereum Classic, Bitcoin Gold and Vertcoin were all hit this way. Every one of them let hashrate that appeared a minute ago rewrite history.</p>
<p>Igneum gives the GPU fleet paid, useful, verifiable work. It gives the proving market a supplier whose electricity cost is close to power and whose price is the subsidy it forgoes, which falls as the network's hash grows. And it makes the right to rewrite history something that must be earned over a month of public mining, not rented for an hour.</p>
</section>
<section id="glance">
<h2>Igneum at a glance</h2>
<p>Five layers. The lottery decides who makes blocks. Proving decides nothing about consensus, which is what keeps the fastest prover from owning the chain. The two are kept apart on purpose.</p>
<div class="figure">
<svg viewBox="0 0 760 560" role="img" aria-label="A block is mined, ordered, executed, proven, then locked by miners" font-family="IBM Plex Sans, system-ui, sans-serif" font-size="12">
<defs><marker id="ar" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"><path d="M0 0L10 5L0 10z" fill="var(--quiet)"></path></marker></defs>
<g fill="none" stroke="var(--quiet)" stroke-width="1.25">
<path d="M250 120V156" marker-end="url(#ar)"></path><path d="M250 224V260" marker-end="url(#ar)"></path><path d="M250 328V364" marker-end="url(#ar)"></path><path d="M250 432V468" marker-end="url(#ar)"></path><path d="M504 400H452" marker-end="url(#ar)"></path>
</g>
<g>
<rect x="50" y="48" width="400" height="72" rx="8" fill="var(--surface)" stroke="var(--line)" stroke-width="1.25"></rect>
<text x="66" y="72" font-size="13" font-weight="600" fill="var(--ink)">1. Mining lottery</text>
<text x="66" y="90" fill="var(--ink)">A random GPU program picks who makes the next block</text>
<text x="66" y="106" fill="var(--quiet)">A new program every hour; the chip model scores the rest</text>
</g>
<g>
<rect x="50" y="152" width="400" height="72" rx="8" fill="var(--surface)" stroke="var(--line)" stroke-width="1.25"></rect>
<text x="66" y="176" font-size="13" font-weight="600" fill="var(--ink)">2. BlockDAG ordering</text>
<text x="66" y="194" fill="var(--ink)">Ordered in parallel, one block a second at launch, rising</text>
<text x="66" y="210" fill="var(--quiet)">A transaction is included in roughly one second</text>
</g>
<g>
<rect x="50" y="256" width="400" height="72" rx="8" fill="var(--surface)" stroke="var(--line)" stroke-width="1.25"></rect>
<text x="66" y="280" font-size="13" font-weight="600" fill="var(--ink)">3. EVM execution</text>
<text x="66" y="298" fill="var(--ink)">Blocks carry transactions only; the proof computes the state</text>
<text x="66" y="314" fill="var(--quiet)">Familiar Solidity, wallets and tooling; differences documented</text>
</g>
<g>
<rect x="50" y="360" width="400" height="72" rx="8" fill="var(--tint)" stroke="var(--ember)" stroke-width="2"></rect>
<text x="66" y="384" font-size="13" font-weight="600" fill="var(--ink)">4. Miners prove the block</text>
<text x="66" y="402" fill="var(--ink)">Shards proven on NVIDIA cards, aggregated into one proof</text>
<text x="66" y="418" fill="var(--quiet)">Lands within about a minute at launch, paid from gas</text>
</g>
<g>
<rect x="50" y="464" width="400" height="72" rx="8" fill="var(--surface)" stroke="var(--line)" stroke-width="1.25"></rect>
<text x="66" y="488" font-size="13" font-weight="600" fill="var(--ink)">5. Sustained-mining finality</text>
<text x="66" y="506" fill="var(--ink)">Miners lock a checkpoint every 30 s, weighted by 30-day history</text>
<text x="66" y="522" fill="var(--quiet)">Fresh rented hashrate has no vote; nothing outside the chain</text>
</g>
<g>
<rect x="504" y="360" width="232" height="72" rx="8" fill="var(--surface)" stroke="var(--line)" stroke-width="1.25"></rect>
<text x="520" y="384" font-size="13" font-weight="600" fill="var(--ink)">External proving jobs</text>
<text x="520" y="402" fill="var(--ink)">Designed: rollups and bridges buy proofs</text>
<text x="520" y="418" fill="var(--quiet)">Same NVIDIA cards, same proof format</text>
</g>
<g fill="var(--quiet)"><text x="260" y="142">winning block</text><text x="260" y="246">ordered blocks</text><text x="260" y="350">state transitions</text><text x="260" y="454">aggregated proof</text></g>
</svg>
<div class="cap">Five layers plus the external proving market. A block flows down the column; outside demand feeds the same miners from the side.</div>
</div>
<h3>Live on the devnet</h3>
<p>The Igneum 2.0 devnet is the network. Its coins have no value and the chain may be reset. What is on it:</p>
<div class="tbl"><table>
<thead><tr><th>Layer</th><th>State</th><th>Since</th></tr></thead>
<tbody>
<tr><td>Mining lottery</td><td>Class v4 (sub-version 3) from the first block: the latency-shadow program, a new program every hour on Apple, NVIDIA and AMD cards, compiled ahead, the era VDF armed, the ladder at rung 0</td><td class="num">block zero</td></tr>
<tr><td>Blocks</td><td>One a second is the target; the live page reads the rate from the observer</td><td class="num">block zero</td></tr>
<tr><td>Difficulty</td><td>Rule v2, a 600-second reference window, from the first block</td><td class="num">block zero</td></tr>
<tr><td>Finality</td><td>Rule v3: a checkpoint every 30 s of chain, locked at two thirds of all 30-day weight, the weight table frozen at the last lock during a pause. No coin is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window, and equivocation strips it for 30 days</td><td class="num">block zero</td></tr>
<tr><td>Proving</td><td>v0 and v1 from the first block: shards are assigned to miners' keys, proven on their NVIDIA cards, aggregated into segment records and carried in blocks; fees calibrated</td><td class="num">block zero</td></tr>
<tr><td>Ember</td><td>The one-click miner, on the devnet channel</td><td class="num">4 Oct 2026, first install</td></tr>
<tr><td>Wallet</td><td>Igneum Wallet on macOS</td><td class="num">5 Oct 2026, first shipped</td></tr>
</tbody>
</table></div>
<p class="src"><b>Source:</b> the facts page carries the network row; the block rate and the lock are rows of the evidence table.</p>
<p>Two caveats, stated here before anyone else states them. Proof verification is enforced in consensus on the Igneum 2.0 devnet from block zero (verifier_in_consensus set, the node's own start line; the chain running since its first block at 17:14 UK on 8 October 2026), which is the prerequisite of the no-rescue network exercise (Deliverable 5) and of the proving economy being a protocol guarantee; the exercise itself is owed, and no block has yet been refused for a false proof on the record. And the devnet is the project's own machines, its rented fleet and a few outside laptops. Nothing here has been reproduced by anyone outside the project yet; the evidence page says so row by row.</p>
</section>
<section id="mining">
<h2>Mining: commodity GPUs, scored against a chip</h2>
<p>Every GPU chain that promised ASIC resistance shipped a fixed algorithm, and a fixed algorithm gets a chip the moment the prize pays for one. Igneum does not assume its algorithm keeps chips away. It assumes a specialised chip exists, seeks profit and stays compatible, and it states how far ahead that chip gets.</p>
<p>Each hour the chain derives a seed from a locked checkpoint one epoch back, passes it through a ten-minute verifiable delay so no miner can see which program a seed implies before choosing whether to publish a block, and feeds it to a deterministic generator. The generator emits a random integer program built from what graphics cards are uniquely good at: wide parallel integer maths, shuffles between the 32 lanes of a warp, and dependent reads spread over a multi-gigabyte dataset that changes daily, so the program waits on memory latency, not on maths or bandwidth. Measured: an RTX 5090 hashes at 95 GB/s of useful 4-byte loads against 1,638 GB/s of sequential writes (engineering log, the RTX 5090 entries). The memory footprint and instruction count are fixed and only the maths sequence is random, so no hour favours one vendor's cards and nobody gains by grinding the seed. Miners compile the program once per hour. Anyone running a node, a wallet or an exchange checks a hash on an ordinary CPU in under ten milliseconds by simulating one warp, so nobody needs a GPU except to mine. Measured: 0.61 ms per warp on one Apple M5 Max core for class v2 and 2.1 ms for class v3 (the mixer at x8, 5 October 2026, one core at load average 5.5, worst cold unit 2.15 ms), 3.4x the class v2 verifier; the 10 ms gate leaves 4.8x (4.6x on the worst cold unit); a 2019-class laptop core is not yet measured.</p>
<p>The hash is a lottery, not a general-purpose cryptographic hash. It has to be unpredictable per nonce, free of any shortcut cheaper than honest evaluation, and free of bias a miner can exploit. It does not need preimage or collision resistance. Open: no analysis of the lottery properties exists yet. It is the first job of the external review in phase 1, and until then the hash is a design claim backed by the measurements below.</p>
<div class="tbl"><table>
<thead><tr><th>Clock</th><th>What changes</th><th>Miner update needed?</th></tr></thead>
<tbody>
<tr><td>Every hash</td><td>The 128 dataset addresses depend on the nonce, so every hash reads different memory. The one-bit select inside the maths costs a chip nothing and is not a defence; the dependent reads are</td><td>No</td></tr>
<tr><td>Every hour</td><td>A new random program</td><td>No, the miner compiles whatever arrives</td></tr>
<tr><td>Every day</td><td>A new dataset</td><td>No</td></tr>
<tr><td>Every six months</td><td>A new instruction mix and memory pattern drawn by the chain from rules fixed at genesis, and a new family of instructions unlocked from a reserve written at genesis, so the program space widens every era. A schedule change against fixed datapaths and human forks, not a surprise: a programmable chip reads every drawn parameter as firmware</td><td>No</td></tr>
<tr><td>Continuously</td><td>The dataset grows on a schedule fixed at genesis, slowly enough that consumer cards keep up for years. Each step is scored against the burden it puts on ordinary cards (Deliverable 3); growth is not counted on to retire a chip</td><td>No</td></tr>
</tbody>
</table></div>
<p>What carries the chip resistance is the scoring rule's result on the placed adversary rows, plus the economics, reported separately in the chip model below. Three properties feed it. <strong>Rotation is an option, not the defence.</strong> A new program every hour, drawn from the chain, its memory pattern with it, and rules that change on a schedule fixed at launch. These schedule changes defeat a chip wired for one datapath and need no human fork, but against a programmable chip that stores the dataset every drawn parameter is firmware, so the security argument does not rest on them. What meets that chip is the latency-shadow work (class v4) and the price per joule (the chip and economy analysis of 6 October 2026, section 5.4; ledger M32). <strong>It waits on memory, not maths.</strong> Every hash is a chain of random reads into a table too big for a chip to carry. Measured (8 October 2026; lane D’s family harness at the acceptance rule’s own 2^20 sample over 4,900 drawn eras, and the chained-cache pass’s reading of the night before): every hash’s 128 dependent reads land across the whole dataset and the distinct-index floor holds at 0.995 on every accepted program; about half of epochs carry one load site whose address bit at the era’s stride rotation is biased, which prices about 1.6 percent of a hash’s reads to a chip storing half the dataset and nothing to a chip storing all of it; the next class folds the product’s low bits before the rotation, so no era lands a biased bit on an address bit. The wait is the same physics for everyone. <strong>Miners hold the switch.</strong> Spare defences are written into the rules, switched off. A miner signal turns one on, at the class-change threshold: miners signal three things at three thresholds, 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. No fork.</p>
<p><strong>The work that waits can grow.</strong> Class v4 adds a block of latency-shadow arithmetic to every hash, about 100,000 integer operations that run while the memory reads are in flight, so a chip that stores the whole dataset still has to pay for a core. That size sits on a ladder fixed at genesis, six rungs from about 100,000 to about 1,000,000 operations, and it moves one rung at a time only when 90 percent of blue blocks in each of seven consecutive days ask for it; it can never move two rungs inside a week and never past a rung the reference verifier cannot check under 10 ms with its sibling thread busy (measured on the build server, 6 October 2026: the first three rungs pass at 8.8, 8.9 and 9.2 ms, the fourth misses by 0.08 ms on a loaded box and stays out until a quiet re-measurement, the two doublings are out at 12.4 and 15.0 ms). What it buys against a chip is scored under the rule in the chip model below. What it costs, per rung, is measured too: the Apple tier gives up 3 points of rate at the first step and 6 more at the second, the RTX 5090 nothing until the second; so the miners who pay for a step are the ones who take it.</p>
<h3 id="chip-model">The chip model</h3>
<p><b>Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes.</b> Class v6 adopts the 64-register window and retains it across every rotation. Current modelling estimates a 1.5x to 3.1x energy-efficiency advantage for the specialised designs assessed as complete machines against the GPU tier, from a board on commodity DRAM at 1.5x to an SRAM-store die at 3.1x (1.5x to 2.3x on the GPU's own node). The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment.</p>
<p><b>The labels.</b> MODELLED. The GPU side is measured (the RTX 5090 at its 1,300 MHz lock on class v4, 8 October 2026). The chip’s core is placed and routed on ASAP7 with SRAM macros and scaled on claimed node factors; the chip’s memory and the rest of the machine (controller, host share, PSU, VRM, cooling) are modelled; no chip is measured, and the chip’s hardware cost is approximate within 2x. Beside it the coexistence verdict at these energies: the DRAM board passes six of the model’s seven conditions, the hybrid coexists only in a growing chain at cheap GPU electricity, the SRAM die fails the cost, hardware, fleet and margin conditions at its reconciled machine cost, and only private supply in a growing network coexists. The k lane’s own placed row amends the figures if it differs. The GPU side is measured: an RTX 5080 at its 1,100 MHz core lock, 2.06 microjoules per hash, and an RTX 5090 at its 1,300 MHz lock, 2.33 microjoules per hash, both under class v4, on the project’s own rigs and rented pods, 8 October 2026; the card’s cost of the window is measured too (a rented RTX 5090 and RTX 4090 at stock, 8 October 2026: within 5 percent per load with the liveness chain, no register spill). The chip side is synthesised and claimed: the clock-gated sequencer core with the 64-register window on ASAP7, scaled to N3 on the foundry’s headline factors (k about 0.37 at N3 and 0.51 node for node for the base core, the gated window adding about 0.13 of k against an adversary with a flop register file; the window’s liveness measured at 61 of 64 values necessary, its cost to the card measured under 5 percent); the window’s k is synthesis-derived and not a lower bound, and the multi-family adversary lane’s first core (its state in a macro) reads the window’s defence as close to nothing, a disagreement between two models that the placed rows settle. The chip’s memory is modelled: the GDDR7 board of the chip model. The placed gated figure is expected near 2.6x to 3.1x a node ahead and 2.3x to 2.7x node for node (approximate) and is served when its row lands.</p>
<p><b>The dataset policy.</b> The dataset’s size is a one-off hardware ticket on specialised designs and a running energy tax on commodity cards: at the proposed 5.5 GiB a locked Blackwell card pays about 14 percent more energy per hash, over the 10 percent budget, while the board on commodity DRAM pays nothing and the SRAM designs pay a hardware cost that does not change their outcome; so the first step sits at 4 GiB, inside the budget, and later steps are taken only when the chain’s own state outgrows them, not on a calendar. (the card rows measured: an RTX 5090 at its 1,300 MHz lock on the project’s own rig and a rented 5090 at stock, 8 October 2026; the chip tickets modelled and approximate; later steps’ costs expected, not measured.)</p>
<p>Three statements, kept separate. The baseline is the hash as it stands under the scoring rule; rotation is an optional improvement to that baseline, not the mechanism the claim rests on.</p>
<div class="tbl"><table><thead><tr><th>Statement</th><th>What it says</th><th>Label and date</th></tr></thead><tbody>
<tr><td>Energy resistance</td><td>Per machine against a locked RTX 5090, node for node and a node ahead: the DRAM board 1.5x (1.3x to 1.7x) and 1.8x; the board with SRAM holding the hottest half of the dataset 1.9x and 2.4x; the SRAM-store die 2.3x and 3.1x; per dollar of hardware at list price 3x to 6x (modelled on the placed full 18-family core, routed 8 October 2026). The honest tier moves to the next node with every GPU generation; a chip must tape out again. Whole machine per tier (synthesis with the SRAM band and node factors, claimed; placed rows to follow): the complete GDDR7 machine about 1.8x the RTX 5090 at its lock per joule node for node and 2.1x a node ahead; 1.6x and 1.9x the RTX 5080; 2.8x and 3.3x the Ada, Ampere and RX 9070 XT cohort; about 1.5x the Apple tier, reported, never headlined.</td><td>MODELLED: placed and routed core energies against the measured RTX 5090 lock row, 8 October 2026, no chip measured</td></tr>
<tr><td>Economic resistance</td><td>Whether a chip gets built depends on development cost, deployment economics and productive hardware lifetime. The first cut of the profitability surface: the price at which a project pays scales as the project cost over its share of the chain times its discounted life, and moves by under 5 percent with the per-joule edge; a fixed-lane chip under rotation needs 4x the price a programmable one needs. No threshold is the headline: the five-year coexistence model (Deliverable 4; its first run is <code>docs/analysis/class-v6/coexistence-model.md</code>, every row modelled) replaces any capex wall: the DRAM board passes six of its seven success conditions at a one to three year life; the SRAM die fails four conditions at its reconciled machine cost; the larger half of a chip's edge is capital cost per accepted hash, not joules. The result, as the model words it: A specialised supplier may earn a normal return; ordinary GPUs remain sufficiently close in total cost, widely obtainable and useful outside mining that new operators can still compete. On today's modelled rows that holds for the chip anyone can build, a stored-dataset board on commodity DRAM, at a productive life of one to three years: its cost per accepted unit of work sits within the range of the best GPU owner and entrant, it passes six of the seven conditions (a third of the network in boards now costs less than a year's revenue at the final hardware price), and a fleet of it holds a minority of the network with GPU entrants still setting the price. For the SRAM-store die the outcome turns on its hardware cost per unit of work, not its energy advantage: at the reconciled machine cost, set by the power train and the shadow core rather than the die, it fails the cost, hardware, fleet and margin conditions at every point of the band, a modest fleet holds about two fifths of a growing network and three fifths of a flat one on arrival and takes every flat or shrinking network within five years, and the only coexistence-shaped outcome is private supply in a growing network; what holds it is the investment decision, since its economics are project economics. A third design, a DRAM board with the hottest half of the dataset in on-board SRAM, sits between the two: it coexists only in a growing network at cheap GPU electricity and fails the cost conditions in a flat or shrinking one, and the dataset's size floor is a real lever on it where it was none on the SRAM die. What holds the die is the investment decision, not the hash; every chip figure here is modelled, not measured, and the chip's hardware cost per unit of work is approximate within 2x. The model holds under every market structure for the DRAM board (private supply, hardware sales, multiple suppliers, with no single supplier above a quarter of the network), and the SRAM die under none but private supply in a growing network; the thresholds live in the model's sensitivity workbook (<code>docs/analysis/class-v6/coexistence-workbook.md</code>), never on a page.</td><td>MODELLED, the coexistence model's first run, 8 October 2026</td></tr>
<tr><td>Response capability</td><td>Rotation is an optional improvement, not the mechanism. A passed rotation boundary proves the rotation works, not that hardware dies. The schedule: a new program every hour, a parameter era every week, a family epoch every 180 days, an emergency vote when miners call one. Rotation costs a chip versatility, not life: the family bank is firmware plus about 43 percent of core cells, and no transition carries an obsolescence credit (modelled).</td><td>measured per boundary, 8 October 2026; the family-bank cost modelled, 8 October 2026</td></tr>
</tbody></table></div>
<p>What a miner sees from this. Class v4 costs a 5090 145 W more unlocked, 88 W more at a 1,400 MHz core lock and 82 W at the best operating points (class v4 at 1,200 MHz, class v3 at 1,300; the knee is 1,300 MHz on both), for 0.2 percent more rate (measured, 7 October 2026; the 80 W read on 6 October was at the app's tuned cap); an M5 Max 16 W more for 1.5 percent, an RX 9070 XT and an RTX 4070 nothing (measured, 6 October 2026). The ladder that sets how much work rides in the shadow starts at rung 0 at genesis and climbs by miner signal; its third rung is inadmissible today because a server core verifies it in 10.85 ms, over the gate (measured, 7 October 2026). The devnet runs class v4 from its first block. Classes rotate on findings and at least yearly; a class change is a release activated by block height. Class v5 is built to cross by height; its dataset keyed by the chain's own state is under evaluation (Deliverable 3) and is not counted as a defence until justified. Class v6 is the design in progress (opened 8 October 2026), with four layers as its spine: per-era draws of the parameters a release now fixes, a dataset whose size tracks the chain state (under evaluation, Deliverable 3), scheduled family epochs by height, and the acceptance floor generalised to every era’s draw. The next test of the model is an internal adversarial pass, not an independent review: three lanes that have never worked on the hash code attack the mixer, the chained cache and the acceptance rule with only what an outsider has (the public kit, the frozen object, the spec, the harnesses) and publish the break or the bound they reach. No outside review has run yet.</p>
<p>No hash has stayed free of chips forever. Igneum does not claim to. It states the gain its own model finds, the economics and the response capability, each separately, and each carries its label. The precedents, as sourced (nameplate and community tables, about 20 percent either way; every figure with its URL and date in the close): Monero has run on RandomX since November 2019, its rules stable since then and its programs varying per hash; one chip shipped against it, Bitmain’s Antminer X5 (September 2023), 46 months after the fork, at 6.37 J per kH at the wall against a stated CPU measurement, an observed comparison, not a ceiling. Bitmain opened Antminer X9 pre-orders on 26 December 2025 for July 2026 delivery, then withdrew the product in mid-May 2026 and refunded buyers before any unit shipped; none has been independently benchmarked. RandomX v2 was released on 25 March 2026 with its mainnet activation pending. Ethash ran 36 months to a first chip worse than a GPU; the iPollo V2H reads about 14x today. Kaspa ran 21 months to its first chip, at 167x to 725x. The commodity cohort Igneum protects is the discrete-GPU population; the Apple row is reported beside it, never as the headline.</p>
<p><b>The scoring rule and the harness.</b> The edge is the minimum over workloads of the maximum over free adversarial designs of the GPU’s joules per hash over the adversary’s, under four conditions: the 10 percent GPU-cost budget at the lock, the verifier limit, cross-vendor correctness and hardware accessibility. The rejected designs stand as negative controls with their measured rows: the long program, the select tree, the wide read, the scratchpad. The two architectural experiments are closed as failures and stay as regression controls: the mixed integer and FP32 branch (measured, 8 October 2026: 15 to 26 percent more card energy per hash against the 10 percent budget) and the connected-state reorganisation (8 October 2026: only the window width reaches the chip). The multi-family programmable adversary (Deliverable 3) is open; rotation is not expected to deliver the missing joule. <a href="https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/design/class-v6-rotating-family.md">The scoring rules and every row, section 10</a>. <a href="https://git.igneum.network/igneum-network/igneum/src/branch/class-v5/docs/design/class-v5-harness/">The harness</a> and <a href="https://git.igneum.network/igneum-network/igneum/src/branch/class-v5/docs/design/class-v5-stored-state.md">its readings</a> (measured, 8 October 2026): the acceptance floor at 0.995 refuses nine of nine hot sets (0.9809 to 0.9919) and 2.435 percent of 4,600 drawn programs, 0 of 61 in the era reading (section 14); the attack families F8, F4, F9 and F1 pass, F8 with a residue of 61 of 64 (section 13); the attempts census and the attempt-3 read (section 0).</p>
<p>One thing takes a person, here and on every chain that exists: writing new code. A chain cannot safely write its own generator, and it cannot safely tell a chip from a wave of honest new cards by hashrate alone. If the design above ever failed, anyone could publish a new generator and miners would switch it on by signalling, as Monero's community can fork. Igneum is built to make that day unlikely, and does not depend on avoiding it.</p>
</section>
<section id="randomx">
<h2>Monero's idea, finished for GPUs</h2>
<p>RandomX has kept Monero on commodity hardware since 2019 by making the mining program random, so the hardware that runs it well is close to the hardware everyone already owns: the one chip that shipped, Bitmain’s Antminer X5 (September 2023), is a board of RISC-V chips at 1.46x per joule over a desktop CPU. The one chip announced against it, Bitmain’s Antminer X9 (pre-orders from 26 December 2025 at 1 MH/s and 2,472 W, about USD 5,600), was withdrawn in mid-May 2026 before any unit shipped; RandomX 2.0 shipped on 25 March 2026 with its mainnet activation pending (monero-project/monero issue 10270). Igneum takes the same principle to graphics cards and adds what RandomX never had.</p>
<div class="tbl"><table>
<thead><tr><th>Property</th><th>RandomX, Monero</th><th>Igneum</th></tr></thead>
<tbody>
<tr><td>Hardware it is built for</td><td>CPUs. GPUs run it badly on purpose</td><td>GPUs. Any card, any vendor. Bit-exact on Apple, NVIDIA and AMD, measured</td></tr>
<tr><td>Random program</td><td>Per hash, interpreted in a virtual machine</td><td>Per hour, compiled to native GPU code. Per hash, the 128 dataset addresses change with the nonce</td></tr>
<tr><td>Dataset</td><td>About 2 GB, the same size since 2019, approximate</td><td>2 GB, growing (the proposed schedule, fixed at genesis: 2 GB, doubling at years 4, 12 and 28); a 4 GB card mines about four years, an 8 GB card about twelve, approximate</td></tr>
<tr><td>Light verification</td><td>256 MB cache on a CPU, milliseconds</td><td>256 MB cache on a CPU (512 MB from year 4), one warp under 10 ms, the gate. Measured 2.1 ms on one Apple M5 Max core for class v3 (3.4x class v2's 0.61 ms); a 2019-class core not yet</td></tr>
<tr><td>Changes over time</td><td>None. A fixed design, unchanged for seven years</td><td>A new program every hour, its memory pattern with it; era draws and reserved families on a schedule fixed at genesis. Nobody touches it</td></tr>
<tr><td>Seed grinding</td><td>Not applicable, the program comes from the hash input</td><td>Closed by a verifiable delay between seed and program</td></tr>
<tr><td>Useful work</td><td>None. Hashing only</td><td>NVIDIA cards prove: from 8 GB alone on the patched server, 16 GB and up beside the miner at the proposed 5.5 GiB dataset (the costed alternative; the first step sits at 4 GiB, where the miner holds less and the rule is not yet measured), 8 and 12 GB cards time-sharing with the miner paused, 24 GB on the stock server (measured on rented cards, 6 and 8 October 2026). Selling proofs to other chains is Designed, not built. AMD and Apple cards mine and do not prove; a prover for them lands when a zkVM ships one</td></tr>
<tr><td>Track record</td><td>About seven years with one shipped chip, Bitmain’s Antminer X5 (September 2023), at 1.46x per joule over a desktop CPU; the one announced beyond it, Bitmain’s Antminer X9, was withdrawn in May 2026 with zero units; RandomX v2 released 25 March 2026, activation pending</td><td>Zero years. Every number above is measured and logged with the commands that produced it. The specification, reference hash, test vectors and simulators are public now (git.igneum.network/igneum-network/spec). The node, the miner and the wallet follow to the same host as the repository is published</td></tr>
</tbody>
</table></div>
<p>Measured so far: the same hourly program, generated on an Apple M5 Max, compiled by Apple's Metal and NVIDIA's CUDA on an RTX 5090, produced identical hashes on both, 192 of 192 across two programs. On a 1 GB dataset the 5090 ran at about 228 million hashes a second and the Mac at about 45 million, both bound by random memory access rather than arithmetic. Those are prototype figures, not mining rates. The first prototype dataset was a closed-form function, and a miner could compute items instead of loading them: measured 111x faster that way on the Mac. The 256 MB cache construction replaced it on 3 October 2026. With the cache, computing items on the fly runs 4.8x slower than loading them, measured on the Mac, and the honest rate is unchanged on both vendors. Open: the same shortcut ratio on NVIDIA and on a discrete AMD card, and the time-memory trade-off between the two measured points. Inside the 5090's 96 MB cache the same program ran nearly six times faster, which is why the dataset starts at 2 GB and grows. On 4 October 2026 a live network crossed an hourly program change on all three vendors with no pause and no rejected block: a Mac at 26.7 million hashes a second, an RTX 5090 at 123 million and an integrated AMD chip at 2.7 million, every hash doing 128 distinct reads of the memory-hard dataset.</p>
</section>
<section id="proving">
<h2>Proving: the miners are the provers</h2>
<p class="lead"><strong>A GPU-secured network for Ethereum-compatible applications and verifiable computation.</strong></p>
<h3 id="architecture">The proof architecture</h3>
<p>Igneum is not an Ethereum L2. Ethereum does not enforce its state or hold its data, so Igneum carries its own consensus security, data availability and cross-chain verification. The architecture is three decisions, kept separate, and one source of extra demand. EVM-compatible execution is what developers build against, through revm. SP1 is the one well-tested proving backend, behind the versioned proving interface; a zkEVM here means the EVM implementation compiled as a program SP1 proves. Igneum's own GPU-mined consensus is where security comes from. External customers are the source of additional proving demand: designed, not built, and out of every revenue assumption.</p>
<div class="tbl"><table>
<thead><tr><th>Decision</th><th>Choice</th><th>State, 8 Oct 2026</th></tr></thead>
<tbody>
<tr><td>What developers build against</td><td>EVM-compatible execution (revm), with a documented set of differences: block context, randomness, two-dimensional fees</td><td>Implemented on the devnet</td></tr>
<tr><td>How execution is proved</td><td>SP1, one well-tested backend behind the versioned proving interface; program identities, verifier versions and security parameters pinned in the protocol; a second backend only where justified</td><td>Implemented: proving v0 and v1 on the devnet. The pinning is Designed</td></tr>
<tr><td>Where security comes from</td><td>Igneum's own GPU-mined consensus: the lottery, GHOSTDAG ordering and miner-only finality</td><td>Implemented on the devnet; external review owed</td></tr>
<tr><td>Additional proving demand</td><td>External customers buying proofs for their own systems</td><td>Designed, not built; out of revenue assumptions</td></tr>
</tbody>
</table></div>
<p><strong>Proven execution is not finality. EVM compatibility is not Ethereum security. ZK is not privacy.</strong></p>
<p>A proof says the state follows from the ordered blocks; the miners' lock decides which blocks are final. Running Ethereum's bytecode does not bring Ethereum's validators. Published state data is public, and privacy needs its own application or protocol design. None of these choices, by itself, answers specialised mining hardware; the chip model is a separate obligation.</p>
<p>Igneum blocks are proven with zero-knowledge proofs, and NVIDIA miners produce them. AMD and Apple cards mine; they do not prove today. Proving is a useful GPU workload that is cheaply verifiable by construction. A proof is right or it is not. Wrapped for light clients, a phone checks it in milliseconds; the wrapping cost is a phase two measurement. Measured so far, the certificate half only: the browser verifier on the home page checks a devnet finality certificate, one BLS aggregate signature over 16 keys and 21 header hashes, in 139 to 155 ms cold and 58 to 68 ms warm in a phone-sized tab on a laptop core (5 October 2026). No phone has been measured, and no wrapped block proof exists yet.</p>
<h3>How a block gets proven</h3>
<p>Blocks carry transactions only and make no claim about state. Every node executes the ordered transactions natively at once, so users see their transaction land in about a second. The execution is then split into shards of a fixed proving cost. Shards are assigned by lot to eight provers for ten seconds, then open to anyone; there is no bond. Provers run them on consumer NVIDIA cards, and the shard proofs are folded by recursive aggregation into one proof for the block. That proof lands on-chain within about a minute at launch (designed). Because the proof computes the state from the ordered sequence, no node accepts a block with a wrong state root. Full nodes also execute every block natively and reject a proof record whose result differs from their own execution, so a forged proof is a light-client problem and never a chain split. Implemented: the native-execution check on every carried proof record, proving v0 on the devnet (specification section 7). The emergency path for a soundness bug in the proof system is a human one: a new proof-system version is written by people and activates only on miner signalling. Invalid transactions are skipped by rule, the way Kaspa skips conflicting spends.</p>
<p>Proving is NVIDIA’s today; AMD and Apple cards mine and do not prove. At the 5.5 GiB dataset floor the miner holds about 6.1 GiB and a compressed shard proof peaks at about 7.5 GiB, so mining and proving together on one card needs a 16 GB card; 8 GB and 12 GB cards time-share, the app pausing the miner for the proof (measured 8 October 2026 on a rented RTX 3060 12 GB and RTX 4060 8 GB: the miner 6,129 and 6,116 MiB resident, the proof 7,525 and 7,532 MiB at its peak, 13.2 s and 8.2 s a compressed shard with the miner paused; the record is `docs/analysis/class-v6/coexist-rows.md`). The earlier rows of 6 October 2026 on eleven rented cards, RTX 3060 to RTX 5090, were taken beside a 1 GiB dataset miner (1.4 GB resident): the RTX 3060 (12 GB) proved the v1 shard beside that miner at an 8.9 GB peak in 37.5 s; the RTX 4060 (8 GB) proved it alone at 7.4 GB in 18.4 s; the RTX 4090 (24 GB) proved it on the stock SP1 server in 5.6 s at 17.4 GB. What changed is the miner’s dataset, not the prover. The patched server that fits the smaller cards is not yet in the shipped app. AMD and Apple cards mine. A prover for them lands when a zkVM ships one. These rows are the proving stage only: the full pipeline is judged, inputs, proving, aggregation, verification, payment, memory and the mining income forgone, and a fast shard does not settle it.</p>
<h3>The proving budget</h3>
<p>Gas prices execution. Proving cost is a different number, so Igneum meters it separately: every transaction pays in both dimensions, and each block has a proving-cost budget set in consensus from measured prover throughput. A transaction that is cheap to run and expensive to prove pays for what it costs the provers. Measured on 5 October 2026 (an RTX 5090 under SP1 6.8.1's GPU prover, the shard size the chain adopts from its fee switch, 30,000 proving gas, about 4.7 million prover cycles): one full shard proves in 4.3 seconds and needs 20.4 GB of GPU memory with the card to itself, so a 24 GB card proves full shards and a 12 GB or 16 GB card does not on this prover build, whose floor is 13.9 GB for even an empty shard; mining and proving on one card needs 32 GB today (the prototype-size shard beside the miner peaked at 30.1 GB) and 24 GB once the adopted shard size is live (22.2 GB beside the miner, 13.2 seconds a shard, measured on the 32 GB card; a 24 GB card has not run it yet). The old 12 GB gate on the roadmap was withdrawn on 5 October until a prover build with a smaller floor was measured; on 6 October a patched server proved the same shard at 7.4 to 8.0 GB alone on eleven rented cards from the RTX 3060 to the RTX 5090 (the real-card table), so the gate returns as measured and the patched server is not yet in the shipped app. The first proofs exist: on 4 October 2026 an RTX 5090 proved a small two-transaction block in 1.4 seconds (2.7 seconds compressed), verified in 0.22 and 0.038 seconds, and a laptop CPU proved a three-shard block end to end in 19 minutes. Later that day the same card proved a full shard at the provisional size, 6.75 million prover gas, which executed in 60.8 million cycles: core proof 8.3 seconds, compressed proof 10.9 seconds, verified in 0.040 seconds; a four-shard block took 44.5 seconds of GPU stages end to end. Shards are assigned and proven on the devnet from block zero. The gate asks for a mid-range card, and an RTX 5090 is not one, so the gate stands open. Once the gate is measured, the budget rises by schedule as hardware improves. The proof system is hash-based, which is what runs on consumer cards, and sits behind a versioned interface. SP1 is the one backend. A replacement is adopted only where justified, by a miner-signalled release, never as an interchangeable second backend, and the chain runs for ever on the current one if none is adopted.</p>
<h3>Proving for everyone else</h3>
<p>The job market for other chains is Designed, not built, and stays out of every revenue assumption until it is. The order: Igneum's own execution first; then one external customer's exact workload with repeat paid jobs; further workloads only where the fleet has a demonstrated edge. As designed, a customer posts a job, a miner wins it, proves it, and is paid, and the market is permissionless. At launch a job is paid on the customer's own chain, in the customer's currency, to a payout contract keyed by miner address, because Igneum cannot yet see Ethereum. Settlement in IGN, with 10% of each fee burned, follows when the proof bridge lets Igneum see the payment, in phase two. The Igneum miner client can also bid on other proving networks and take the best price, where a miner chooses to hold their collateral: Boundless provers post ZKC and Succinct provers stake PROVE (approximate, from their documentation). The proving market is small today. Igneum does not depend on it. We know of no proof-of-work chain that sells proofs to other chains.</p>
</section>
<section id="finality">
<h2>Speed and finality, powered by miners alone</h2>
<h3>Speed</h3>
<p>Igneum orders blocks with GHOSTDAG, the BlockDAG consensus Kaspa has run in production since 2021 (approximate), forked from rusty-kaspa. Blocks arrive in parallel and are ordered rather than orphaned, so the chain runs at one block a second at launch with scheduled steps to four and ten, the step plan Kaspa used for its own block-rate rise (approximate). A transaction is included in the DAG in about one second (an Ethereum slot is twelve) and locked by miners in about two minutes (Ethereum reaches finality in about thirteen, approximate). Inclusion is not confirmation on either chain, and the two finality mechanisms differ: Igneum's lock is a vote of miners weighted by 30 days of blocks, Ethereum's is economic, backed by slashed stake. Emission per block is a schedule keyed to difficulty-adjusted time, and every block in the window is paid at that rate, red or blue, so coins track blocks within the accuracy of the difficulty controller.</p>
<h3>Finality</h3>
<p>Every 30 seconds of chain a checkpoint forms, deep enough past the tip that the DAG will not reorder it. Every miner with at least 100 blocks in the last 30 days signs it, and the checkpoint locks when signatures representing two thirds of all the mining weight of those 30 days arrive. Once a checkpoint is locked it overrides the heaviest chain, so fresh hashrate cannot reorganise past it. Two thirds of 30-day weight can. In the chain's first 30 days no checkpoint locks at all: the rule waits until the window holds 30 days of history (Implemented, the first-month gate, measured on test networks on 4 and 5 October 2026), so the chain runs on proof of work and its 12-hour finality depth the way every new proof-of-work chain does. On the devnet, whose window is two hours, the first lock came two hours after genesis, at 77.4% of all weight from 17 vote keys (4 October 2026).</p>
<div class="pull">The word sustained is the whole defence. Block rewards go to whoever mines, new or old. The right to lock history is earned.</div>
<p>A miner's vote weight is simply the blocks it has mined over the trailing 30 days, measured by work, so splitting into many keys buys nothing and joining a pool costs nothing. Hashrate that arrived today holds almost none of it. Even an attacker producing every block on the chain, with honest miners gone, would need ten days of mining in public to hold a third of the weight, and twenty to hold two thirds. An attacker matching the honest network needs twenty days for a third and never reaches two thirds while the honest miners keep mining. Rental is priced by the hour. The only route left is to drive honest miners off the chain and hold two thirds for a month on the public hashrate charts, which is the same limit Bitcoin lives with, with a month's warning attached. Pools carry their hashers' votes, so vote concentration equals pool concentration, and it is public (today's behaviour, as built). The pin replaces it: vote keys stay with the miner at protocol level: the member's retained voting key is committed into its work, payment aggregation is separate and verifiable, and pool identity substitution is resisted (a pin of Igneum 2.0, pools and participation; not yet shipped).</p>
<p>Two further rules close the gaps. A lock needs two thirds of all 30-day weight, so finality pauses whenever less than two thirds of that weight is connected and signing, until it returns or ages out of the window, up to 30 days, and the chain runs on proof of work meanwhile. The node reports the pause. A key that stops signing is reported as absent within two hours, which is how operators see a pause coming. Beneath the latest lock the depth to rely on is the finality depth: a node never switches to a chain forked more than 12 hours of median time back, and a certified checkpoint shortens that to its own age. Kaspa's one-hour merge depth is a limit on which old blocks a new block may merge, not a reorganisation bound. Signing two different checkpoints at the same height is equivocation, provable by anyone, and it strips the key of its vote for 30 days.</p>
<h3>What is not here</h3>
<p>No coin is staked. The only thing at stake is 30 days of public work: a vote key's weight is its blue blocks over the window, and equivocation strips it for 30 days. No coin-holder class votes on anything. No anchoring into Bitcoin or any other chain. Nothing in Igneum's consensus depends on anything outside Igneum.</p>
</section>
<section id="building">
<h2>Building on Igneum</h2>
<p class="lead"><strong>A GPU-secured network for Ethereum-compatible applications and verifiable computation.</strong></p>
<p>Contracts built for Ethereum deploy with the same Solidity, the same bytecode, the same wallets and tools, and a different chain id. Compatibility is shown, not assumed: representative contracts, wallet fee estimation, indexing, failed transactions and receipts are tested as a product deliverable, and the differences are documented (block context, randomness, two-dimensional fees). Builders get Ethereum semantics with one-second inclusion, finality in about two minutes, and gas priced for a chain that is not congested.</p>
<p>Three things Igneum offers at the base layer that we know no other EVM chain offers.</p>
<ol>
<li><strong>Proving as a native primitive.</strong> A contract can request a proof of any computation and pay for it in gas, and the miners produce it. A game proves a fair shuffle. A lending market proves its solvency. A rollup elsewhere posts a job and gets its proof back. We know of no other EVM chain with a prover network in its base layer.</li>
<li><strong>Light clients.</strong> Because every block is proven, a phone or a browser verifies Igneum's state from one proof and a locked checkpoint it is given. Making the checkpoint itself self-verifying, which is what removes the multisig from bridges, needs a consensus proof and is phase two.</li>
<li><strong>Rollups that settle here.</strong> A rollup posting to Igneum gets its proofs from the same miners that secure it, in the same flow. Settlement and proving in one place costs less than paying a proving network and a settlement layer separately.</li>
</ol>
<p>The first apps, a DEX and a lending market, ship at genesis so there is somewhere to use the coin from day one. No bridge is official: anyone may run one at their own risk, and the proof bridge arrives with the consensus proof in phase two.</p>
<h3>Why build here</h3>
<p>Not for speed. Fast EVM chains filled with copied Ethereum contracts and emptied when incentives stopped. Three things no L2 can offer. Keep your Ethereum deployment.</p>
<ol>
<li><strong>Proofs priced by the subsidy forgone.</strong> A contract requests a proof of any computation and the miners produce it. Their cards already run and are paid by emission, so a job has to beat the lottery income the card forgoes while it proves. That is the price a prover must charge, as a formula with network hash as the input: per shard, (card hash ÷ network hash) × 0.8 × 31.688 IGN × shard seconds, plus electricity, which is under a cent per billion cycles on every card. It falls as one over network hash: at the devnet's 1.16 GH/s a quote is 100 to 300x the published market rate; a card proving beside its miner is competitive near 100 GH/s (the economy analysis of 6 October 2026, sections 3.1 and 4.1, approximate beyond the one card measured; ledger E20). Verification is folded into the chain's own proof; you ship no verifier. The job's base fee rises with the backlog, published at the phase 4 job market.</li>
<li><strong>Users who were not paid to arrive.</strong> Every miner is a funded wallet. Pools, payout contracts, hardware finance and hashrate forwards have customers before any consumer app does. Block rewards can pay straight to a contract.</li>
<li><strong>A share of fees, with the number stated.</strong> 20% of every priority fee goes to the contracts whose code ran, per call frame, to the payee registered at deployment. Libraries are paid at their code address. Factories pass their registration to what they deploy. At launch fee levels this is a property, not an income: a million 100,000-gas calls a day at a 1 gwei tip pays about 7,300 IGN a year, with 1 gwei taken as a billionth of an IGN (the base unit is Open). It grows with traffic and nothing else.</li>
</ol>
<p>Ethereum stays your settlement. Move heavy compute to Igneum and return the result as a proof Ethereum verifies for about 250,000 gas. Igneum reads Ethereum's finality trustlessly from launch. Ethereum reads Igneum trustlessly in phase two. Until then, trust the bridge's operator.</p>
<p>No stablecoin and no official bridge at genesis. Grants come from founders' mined coins, for ports, audits and integrations, never for a user count. Execution is immediate, the miner lock lands in about two minutes; a withdrawal waits for the lock.</p>
</section>
<section id="economics">
<h2>Economics</h2>
<p>The coin is IGN. It is gas and the proving currency, and part of every payment on Igneum is burned. Outside customers pay in their own currency on their own chain at launch; settlement in IGN with a 10% burn follows when the proof bridge lets Igneum see the payment, in phase two.</p>
<h3>Supply</h3>
<p>Fair launch. No premine, no pre-sale, no allocation to anyone. Hard cap of 4 billion IGN, approached and never reached, because emission starts at 1 billion a year and halves every two years for ever. Nearly a quarter of all supply is mined in the first year and half in the first two. Emission ramps from 10% to 100% over the first 30 days so that nobody takes the first month before the rest of the world hears about it.</p>
<div class="figure">
<svg viewBox="0 0 760 300" role="img" aria-label="Half of the 4 billion cap is mined in the first two years" font-family="IBM Plex Mono, monospace" font-size="12">
<text x="40" y="26" font-family="IBM Plex Sans, system-ui, sans-serif" font-size="15" font-weight="600" fill="var(--ink)">Half of the 4 billion cap is mined in the first two years</text>
<text x="40" y="46" fill="var(--quiet)">Millions of IGN issued per year, halving every two years for ever</text>
<line x1="40" x2="720" y1="250" y2="250" stroke="var(--line)"></line>
<g fill="var(--ember)">
<rect x="51" y="70" width="34" height="180" rx="3"></rect><rect x="108" y="70" width="34" height="180" rx="3"></rect>
</g>
<g fill="var(--surface-2)" stroke="var(--line)">
<rect x="164" y="160" width="34" height="90" rx="3"></rect><rect x="221" y="160" width="34" height="90" rx="3"></rect>
<rect x="278" y="205" width="34" height="45" rx="3"></rect><rect x="334" y="205" width="34" height="45" rx="3"></rect>
<rect x="391" y="227.5" width="34" height="22.5" rx="3"></rect><rect x="448" y="227.5" width="34" height="22.5" rx="3"></rect>
<rect x="504" y="238.7" width="34" height="11.3" rx="3"></rect><rect x="561" y="238.7" width="34" height="11.3" rx="3"></rect>
<rect x="618" y="244.4" width="34" height="5.6" rx="3"></rect><rect x="674" y="244.4" width="34" height="5.6" rx="3"></rect>
</g>
<g fill="var(--ink)" text-anchor="middle">
<text x="68" y="62">1000</text><text x="125" y="62">1000</text><text x="181" y="152">500</text><text x="238" y="152">500</text><text x="295" y="197">250</text><text x="351" y="197">250</text><text x="408" y="220">125</text><text x="465" y="220">125</text><text x="521" y="231">63</text><text x="578" y="231">63</text><text x="635" y="237">31</text><text x="691" y="237">31</text>
</g>
<g fill="var(--quiet)" text-anchor="middle">
<text x="68" y="270">1</text><text x="125" y="270">2</text><text x="181" y="270">3</text><text x="238" y="270">4</text><text x="295" y="270">5</text><text x="351" y="270">6</text><text x="408" y="270">7</text><text x="465" y="270">8</text><text x="521" y="270">9</text><text x="578" y="270">10</text><text x="635" y="270">11</text><text x="691" y="270">12</text>
</g>
<text x="720" y="290" text-anchor="end" fill="var(--quiet)">Year after launch</text>
</svg>
<div class="cap">Emission schedule, fixed in consensus. 3,938M IGN in the first 12 years of a 4,000M cap.</div>
</div>
<h3>Where every coin of emission goes</h3>
<div class="tbl"><table>
<thead><tr><th>Share</th><th>Goes to</th><th>Why</th></tr></thead>
<tbody>
<tr><td class="num">80%</td><td>The miner who wins the block</td><td>Pays the hashrate that secures the chain</td></tr>
<tr><td class="num">20%</td><td>The proving pool: shard provers and aggregators</td><td>For a standing prover population that does not have to hash. On the devnet today the coinbase's 20% output goes to an unspendable script tagged <code>igneum-proving-pool-v0</code> and is burned there. Provers are paid from a separate escrow in the execution state, credited by rule with the same 20% of each blue block's subsidy and released per shard against valid proof records (Implemented, proving v0, since 5 October 2026). On the Igneum 2.0 devnet consensus verifies the carried proof from block zero (verifier_in_consensus set), so a block carrying a statement without a valid proof is refused; an earlier devnet checked only the record's statement against native execution, where a producer could claim shard pay with a false proof (the no-rescue network exercise, Deliverable 5, is still owed). Note: unclaimed pool credit is today stranded in the escrow, no rule returns it; the fix rolls an unproven shard's credit into the next proven segment's pool (designed). Open: the single coinbase payout that replaces the burn, and whether it reclaims the share burned so far</td></tr>
<tr><td class="num">0%</td><td>Treasury, foundation, team or stake</td><td>There is no coin-holder class in consensus and no tax on emission</td></tr>
</tbody>
</table></div>
<h3>Where fees go</h3>
<p>The base fee of every transaction is burned in full, Ethereum's rule, so a miner cannot fill blocks with its own transactions for free. The priority fee splits two ways: 80% to the miner and provers of that block, 20% to the apps whose code ran, by gas consumed inside each. External proving fees, once they settle on Igneum, pay 90% to the provers who delivered and burn 10%. The hard cap fixes supply. Emission is untouched by any of this: every coin minted still goes to miners and provers.</p>
<h3>Every payment route</h3>
<p>One row per route, so operator income and protocol income never blur. The protocol pays no address of its own, and a burn pays nobody. Rows 1 to 5 are the protocol. Row 6 is the project's software, outside the protocol, and is never added to the other five.</p>
<div class="tbl"><table>
<thead><tr><th>Route</th><th>Currency</th><th>Recipient</th><th>Fee</th><th>Burn</th></tr></thead>
<tbody>
<tr><td>1. Emission, per block</td><td>IGN, new coins on the schedule above</td><td>80% the block's miner, 20% the proving pool for the provers of that block</td><td>None</td><td>None. Implemented in consensus: the 80/20 coinbase on the devnet</td></tr>
<tr><td>2. Base fee, both gas dimensions</td><td>IGN</td><td>Nobody</td><td>The base fee the chain sets per block</td><td>All of it. Implemented on the devnet</td></tr>
<tr><td>3. Priority fee</td><td>IGN</td><td>80% the block's miner and provers; 20% the apps whose code ran, per call frame</td><td>The tip the sender sets</td><td>The share of any frame in an unregistered contract. Implemented on the devnet</td></tr>
<tr><td>4. External job, at launch</td><td>The customer's currency, on the customer's chain</td><td>The miner who delivered, through a payout contract keyed by miner address</td><td>Priced in the customer's money per proof, at or above the subsidy the prover forgoes (a formula in network hash, under Building on Igneum, never a fixed number); the customer chain's own bond and slashing apply</td><td>None; Igneum cannot see the payment. Designed</td></tr>
<tr><td>5. External job, after the proof bridge</td><td>IGN, on Igneum</td><td>90% the provers who delivered</td><td>The job fee</td><td>10%. Designed, phase two</td></tr>
<tr><td>6. The official client's dev fee</td><td>IGN</td><td>The project, as operator income, never the protocol</td><td>default-on, switchable, 1 percent of the producer share: 1 block template in 100 requested with the dev address; off with one flag</td><td>None. Implemented, measured on a test network 4 October 2026</td></tr>
</tbody>
</table></div>
<p class="src"><b>Sources:</b> specification sections 2.5 and 5.1 to 5.4; the engineering log for the devnet receipts and the dev-fee count.</p>
<h3>Security after the subsidy</h3>
<p>The cap stays at 4 billion. There is no tail emission. The schedule is a bet, not a measurement: a halving halves emission income overnight if price and fees do nothing. Kaspa's steeper monthly reduction kept its hashrate while its price rose (approximate). Long term, security has to be paid by fees and, if it is built and bought, the proving market. The external market is Designed, not built, and is out of the numbers below. As designed, outside customers buy proofs as dollars-priced work settled in IGN, and 90% of every job goes to the provers who delivered it. The table shows the first year in which the block subsidy on its own pays miners less than the power of about 3,000 consumer cards, at three flat prices. The prices are inputs chosen to span two orders of magnitude. The model (modelled, 3 October 2026) runs a 300 W card at 124 MH/s on electricity at USD 0.12 per kWh. One rule sits beside the cap. If external proving revenue is under one fifth of the block subsidy over any 90-day window after year 5, the question of a tail reward goes to the miners' signalling vote. The protocol never changes emission by itself.</p>
<div class="tbl"><table>
<thead><tr><th>Price per IGN</th><th>First year the subsidy alone pays under the power of 3,000 cards</th><th>Subsidy to miners that year</th></tr></thead>
<tbody>
<tr><td class="num">USD 0.005</td><td>Year 7</td><td class="num">USD 500,000</td></tr>
<tr><td class="num">USD 0.02</td><td>Year 11</td><td class="num">USD 500,000</td></tr>
<tr><td class="num">USD 0.10</td><td>None in the first 14 years</td><td class="num">USD 1,250,000 in year 14</td></tr>
</tbody>
</table></div>
<h3>No fund, no foundation, no fee to the team</h3>
<p>There is no development fund. A switch that routes money to an address somebody controls is the first thing a critic points at, so Igneum has none. The protocol carries no fee to any team, foundation or fund. The project earns in the open, and this is the full list: the optional 1% dev fee in the Ember miner software, off with one flag and audited on the chain; the provers it runs in the job market; any pool it operates; and the app share on the contracts it deploys, like anyone else. None of it is in the protocol, and the first item is the one a critic should quote: for as long as miners run Ember with the fee on, 1 block in 100 pays the project. If the community ever wants a grant mechanism, miners can add one by signalling.</p>
<h3 id="in-law">What the chain is, in law</h3>
<p class="note"><strong>Not legal advice.</strong> These are the facts of the design that the rules of each region turn on; nothing here is a promotion of anything.</p>
<ol class="law">
<li><strong>No issuer, no offeror, no sale.</strong> Every coin is created automatically as a reward for the maintenance of the distributed ledger or the validation of transactions, and in no other way.</li>
<li><strong>The sustainability indicators are published.</strong> The indicators of Delegated Regulation 2025/422 (energy in kWh a year from the network’s hash rate and the measured microjoules per hash, intensity per transaction, the regional mix when it is known) are published by the project every era, so a service provider in the EU can list the coin without asking.</li>
<li><strong>No financial promotion.</strong> No price, no “buy”, no “invest”, no return language anywhere. The earnings screen shows hash and IGN, never a currency.</li>
<li><strong>The reference pool never holds a member’s balance.</strong> Payouts come straight from the coinbase split; the pool coordinates, it does not keep custody.</li>
<li><strong>The job market settles peer to peer on the chain.</strong> There is no operator account and no dollar leg in the protocol: the dollar figure is a quote, the settlement is IGN.</li>
<li><strong>Open software, no coins by right.</strong> The software is published under an open licence by a company that holds no coins by right and runs no service the chain’s consensus depends on. There is no dev fund.</li>
<li><strong>Mining may be restricted where you are;</strong> you are responsible for checking. The miner asks your region at first run and refuses the regions where mining is banned (on 7 October 2026: ten regions of Russia and Moscow from 15 August 2026, and China).</li>
<li><strong>No privileged key.</strong> No key can mint, pause or upgrade the chain; the only way a rule changes is miners signalling for it, and nothing requires them to.</li>
</ol>
</section>
<section id="miners">
<h2>For miners</h2>
<p>Igneum is built for the GPU fleet that has had no home since 2022. Here is what it offers and what it asks.</p>
<h3>Three income streams, one balance</h3>
<div class="tbl"><table>
<thead><tr><th>Stream</th><th>Paid by</th><th>Moves with the IGN price?</th></tr></thead>
<tbody>
<tr><td>Block reward</td><td>Emission, 80% to the winner</td><td>Yes</td></tr>
<tr><td>In-chain proving</td><td>The 20% proving pool plus the proving share of every block's gas (on the devnet, paid from the execution-state escrow; see Economics)</td><td>Yes, mostly</td></tr>
<tr><td>External proving jobs</td><td>Rollups and apps on other chains, priced in their money (Designed, not built)</td><td>No, but the market is not built and is upside, not a promise</td></tr>
</tbody>
</table></div>
<p>A block pays its miner whether or not anyone buys a proof that day. The lottery pays 80 percent of every block from emission; proving is the second income, never the only one. Every useful-work chain on record dropped its miners the day the work stopped paying; Igneum’s miners are paid for the block first.</p>
<p>The size of that third stream today, in numbers: all of Ethereum L1's proving is about USD 36 a day at the September 2026 tracker cost (USD 0.005 a block, 7,200 blocks a day; the tracker figure is a secondary source), against about USD 13,700 a day of Igneum's year-1 emission at USD 0.005 per IGN (31.688 IGN a block, 86,400 blocks a day; the price is an input, not a forecast). So external proving is a small second income at launch and the lottery pays the bills; for proving to become the main income the paid demand would have to grow about 1,000x in dollars (the chip and economy analysis of 6 October 2026, section 3.11; ledger E19).</p>
<p>The honest bear-market case rests on cost. A miner's card is already running and the power is often domestic, so Igneum miners' electricity cost in the proving market is close to power. The price they must charge is another matter: the price a prover must charge is the subsidy it forgoes while it proves, which falls as one over network hash, so the edge over data-centre provers appears only once the network's hash is large (near 100 GH/s for a card proving beside its miner) and is nothing more. Which of the two in-chain streams pays more per GPU-second depends on the size of the fleet: measured on 4 October 2026, three machines at 275 million hashes a second, a second of hashing paid about 4.9x a second of proving the pool share; at 10,000 cards the same arithmetic favours proving by about 930x. That is arithmetic on measured devnet rates, approximate, not a market measurement.</p>
<h3>Hardware</h3>
<p>The dataset starts at 2 GB and grows (the proposed schedule, fixed at genesis: 2 GB, doubling at years 4, 12 and 28, the average of half a gigabyte a year), so a 4 GB card mines for about four years and an 8 GB card for about twelve, approximate. NVIDIA cards prove: from 8 GB alone on the patched server, 16 GB and up beside the miner at the proposed 5.5 GiB dataset (the costed alternative; the first step sits at 4 GiB, where the miner holds less and the rule is not yet measured), 8 and 12 GB cards time-sharing with the miner paused, 24 GB on the stock server (measured on rented cards, 6 and 8 October 2026). NVIDIA and AMD cards both mine, because the mining program is generated for the architecture both share; only NVIDIA cards prove today. Apple's chips are GPUs with unified memory, so Macs mine too, at about a fifth of a flagship card: Measured, 26.7 against 123 million hashes a second, an Apple M5 Max beside an RTX 5090, mining side by side, 4 October 2026. A Mac is a poor miner per dollar. There is no CPU mining lane, on purpose, because CPU mining is what botnets farm. Nodes, wallets and exchanges need no GPU at all.</p>
<h3>What a miner's hour looks like</h3>
<p>The card hashes the lottery continuously. On an NVIDIA card, when the client sees a shard it can win (or, once the job market is built, an external job), it switches the card to proving for a few seconds, posts the proof, and goes back to hashing. The client does the switching and the miner sees one balance.</p>
<p>The protocol carries no fee: no dev fund, no cut to any team. Ember, the miner software, takes an optional 1% dev fee, the way other GPU miners do. One block template in 100 is requested with the dev address instead of yours, by a counter, not a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. One flag turns it off (<code>--dev-fee 0</code>, a switch in the app, a line in the HiveOS config). The miner prints the fee and the address when it starts. Any other client is welcome.</p>
<h3>One click, for everyone else</h3>
<p>Farm operators get a HiveOS package. Everyone else gets Igneum Ember: install it on Windows, macOS or Linux, press Start, and the card is mining to a key the app made for you. It is the same client with a face on it. Implemented in Ember (7 October 2026): the app shows the key once and has you save it before mining starts, or takes an address you already have; the dashboard shows each card's hash rate, blocks found and accepted by the node, the node's height and peers, the next hourly program, the finality votes sent, and a proving tile with shards assigned, submitted and paid and the verifier state; the chain label names the devnet and the welcome screen says nothing is bought or sold; NVIDIA cards are capped at 80% of their default power limit for stability, with a sweep that looks for the best hash per watt, not yet measured on a card; proving the shards the chain assigns is a switch in Settings (proving v0), beside the 1% dev fee switch, finality voting, and signed updates that install themselves at a quiet moment with a switch to turn that off. It shows no earnings in IGN or in any currency, and it has no hardware-wallet path. Roadmap, Designed and not in the app: earnings per block in IGN with the network named, a figure in your currency, mining paused while you game, and a hardware wallet for your key. Ember is downloaded only from this domain, with the version and size on the button and the hash in the signed manifest the app checks. The next section says what is shipped and what is still a design. Nobody from Igneum will ever ask for your seed. Mining never runs in a browser, because browser compute is slow and browser mining has meant malware since Coinhive. The browser is for the dashboard, and for verifying the chain.</p>
<h3 id="devnet-terms">Devnet terms</h3>
<p><strong>No value.</strong> Devnet IGN cannot be sold, bought or redeemed, now or at mainnet. There is no airdrop, no points scheme and no promise tied to devnet balances. Mainnet starts from an empty genesis.</p>
<p><strong>Resets.</strong> The devnet may restart from a fresh genesis, without notice. Balances, contracts and history do not carry over.</p>
<p><strong>What the app sends home.</strong> The app version, a random machine id made at install, your operating system, the node version, the hash rate, and the app, node and miner logs (which name the address the card mines to). They go to the project's log intake, a service Igneum runs on its host, and are read by the maintainers to find faults. Never your seed phrase, never a key, never a file you did not make with the app. Nothing is sold or shared.</p>
<p>Wallet set-up for MetaMask: <a href="/metamask">chain id, RPC and the one-click button</a>. The miner software takes an optional 1% fee, off with one flag; the protocol carries no fee to anyone.</p>
<h3>Fair launch, announced</h3>
<p>Launch date and miner software published a month ahead. Pools live before launch. HiveOS support on day one. The founders mine from genesis like everyone else, with disclosed addresses and the same software. Nobody has coins before block one. The first 30 days of mainnet run on proof of work alone, with no locked checkpoint, while vote weights build; anyone crediting deposits in that month should treat Igneum as plain proof of work with a 12-hour depth.</p>
</section>
<section id="ember">
<h2>Ember, the miner</h2>
<p class="lead">Igneum Ember is the one-click miner. It runs the node, mines the hourly program, proves shards and keeps your key, on Windows, macOS and Linux.</p>
<p>Ember is a supervisor with a face. It starts a node, waits until it is synced, starts one miner per card, reads every line they print into the dashboard, and restarts what fails. It has run the devnet's cards since 4 October 2026. Everything in the first table is in the shipped app. The second table is the six levers set on 4 October 2026 to make it the fastest miner for this chain, each with its state and what has been measured.</p>
<h3>What it does</h3>
<div class="tbl"><table>
<thead><tr><th>Feature</th><th>What happens</th></tr></thead>
<tbody>
<tr><td>One click</td><td>Install, press Start. Ember runs its own node, syncs it, and starts one miner per card. Windows, macOS and Linux. Farms get a HiveOS custom-miner package with the same binaries</td></tr>
<tr><td>Any card</td><td>NVIDIA, AMD and Apple silicon are detected with their real names. CUDA on NVIDIA, OpenCL on AMD and Intel, Metal on Apple. No toolchain on the machine: the GPU program is compiled at run time from the pack the node hands over</td></tr>
<tr><td>A key made for you</td><td>A payout key is made on your machine and kept in a file only your user can read. Ember shows it once and has you save it before mining starts. Paste your own address instead if you have one</td></tr>
<tr><td>Hashing and proving in one client</td><td>The same app mines the lottery and proves the shards the chain assigns to its keys, on the same card. Proving is a switch in Settings. The tile shows assigned, proving, submitted and paid</td></tr>
<tr><td>Several identities per card</td><td>Each card carries as many vote keys as you choose, so a large card holds the finality weight its blocks earn. The HiveOS config suggests 8 on a large card and 2 on a small one</td></tr>
<tr><td>Signed updates</td><td>Ember checks a signed manifest hourly, downloads the release, checks its hash, and installs it at a quiet moment: node synced, no hour boundary within 3 minutes, no worker starting. Machines take turns, one minute of the hour each. A release that fails to start twice is rolled back. One switch turns the automatic install off</td></tr>
<tr><td>Signed remote jobs</td><td>The project's own machines take jobs signed by the release key and addressed to named machines: a benchmark, a build, a restart. A job runs once per id and never on a machine it does not name. A switch in Settings turns them off</td></tr>
<tr><td>Watchdog</td><td>A miner that prints nothing for 90 s, or reports zero for 60 s while the node is synced, is restarted. A worker that reports work it did not do, or returns a hash the CPU re-check rejects, is restarted by the miner itself. A node that stops answering is restarted</td></tr>
<tr><td>Dashboard</td><td>Per card: rate, accepted and rejected blocks, temperature, draw, MH per watt, the kernel variant in use, the proving state, and every event. Served on this machine only, behind a per-launch token</td></tr>
</tbody>
</table></div>
<p class="src"><b>Source:</b> the app's engine, detection, keys, prover, updater, jobs and watchdog modules (the app source), the HiveOS package (the HiveOS package). Design, not yet measured on a real card: the watchdog rules and the fault guards, which were measured against a fake worker only (engineering log, "miner fault guards and the app watchdog", 4 October 2026).</p>
<h3>Six levers</h3>
<div class="tbl"><table>
<thead><tr><th>Lever</th><th>What it does</th><th>State, 5 Oct 2026</th><th>Measured</th></tr></thead>
<tbody>
<tr><td>1. Compiler race every hour</td><td>At every hourly program the worker compiles up to 17 variants of the kernel (unroll, load path, register budget, threads per block), checks each bit for bit against the base kernel, times each for 2 s with mining paused, and keeps the fastest for the hour. The hash output is bit for bit the same</td><td>Shipped in the Metal and CUDA workers</td><td>+17.3% on the genesis seed and +21.2% on the hourly seed, Apple M5 Max, Metal, 14 variants, under load, ratios only. The RTX 5090 race is built and not yet run</td></tr>
<tr><td>2. Per-card auto-tune from the fleet</td><td>Every race writes a record to the fleet log. The best variant per card model is aggregated and sent back to every machine inside the signed update manifest, so a new card starts from the fleet's best and keeps racing</td><td>Shipped. The fleet is small, so no table yet</td><td>No fleet table yet</td></tr>
<tr><td>3. Hash per watt</td><td>Steps an NVIDIA card's power cap from 100% to 50% of its default in 10% steps, holds each for 60 s, and keeps the best MH per watt. The tile shows live MH per watt. The sweep never restarts the worker, so the hour's program is never lost</td><td>In the app for NVIDIA cards. AMD and Apple: not supported</td><td>The first sweep on a card is pending. The RTX 5090 drew 290 W at p95 under a 460 W cap, so the cap did not bind</td></tr>
<tr><td>4. Template latency</td><td>The miner subscribes to new templates instead of polling, the node builds the next template ahead, and the workers switch without draining the batch. Target under 50 ms from a new block to the card working on it, solo against the local node</td><td>Shipped</td><td>Switched p50 46 to 52 ms, p90 118 to 130 ms, 3-node fast-time network, CPU miners, 0 rejected</td></tr>
<tr><td>5. Never lose a second</td><td>The next hour's program is compiled ahead and swapped in place. The watchdog, the restarts, the CPU re-check of every found hash and per-worker health on every tile keep the card hashing</td><td>Shipped</td><td>Swap 0.01 ms on the Mac and 0.00 ms on the RTX 5090, 0 rejected, mining live. Fake-worker guards: trip 0.0 s, worker back in 2.0 s; a silent worker restarted at 60 s</td></tr>
<tr><td>6. Prove it in public</td><td>Every measured rate, with the card, the miner version, the date and the log entry it came from, on one page</td><td>Live</td><td><a href="/miners">The bench table</a></td></tr>
</tbody>
</table></div>
<p class="src"><b>Measured:</b> engineering log, "miner performance: variant racing" (lever 1), "first hourly program swap" and "miner fault guards and the app watchdog" (lever 5), 4 October 2026; the miner-latency gate (lever 4), 5 October 2026; the efficiency-sweep plan, the RTX 5090 log of 4 October 2026 (lever 3). Levers 2 and 3 are shipped code with no fleet measurement yet.</p>
<h3>The software's fee, not the protocol's</h3>
<p>The protocol is fee-free: no dev fund, no fee to any team, foundation or fund. Ember takes a 1% software dev fee, the norm for GPU miners: default-on, switchable, 1 percent of the producer share (the 80% of emission that pays the block's miner; the proving pool is paid per record and carries none of it). One block template in 100 is requested with the dev address instead of yours, by a counter, never a random draw, so it is exactly 1 in 100 and anyone can check it from the source or from the chain. A fee block still carries your vote key, so it still adds to your finality weight. Ember prints the fee and the address when it starts, shows it in Settings next to a switch, and <code>--dev-fee 0</code> turns it off, as does <code>DEV_FEE=0</code> in a HiveOS flight sheet. Any other client is welcome.</p>
<p class="src"><b>Measured:</b> engineering log, "the software dev fee measured on a test network", 4 October 2026: 9 fee blocks in 785 from two fee-paying miners, 0 from the control at <code>--dev-fee 0</code>, the chain and the miners' counters equal.</p>
<h3>What Ember does not claim</h3>
<ul>
<li><strong>The race gain on NVIDIA.</strong> Unknown until the RTX 5090 job runs. The Mac's figure is a different compiler and a different memory system.</li>
<li><strong>A measured sweep.</strong> The hash-per-watt sweep has not yet run on a card.</li>
<li><strong>HiveOS on a rig.</strong> The package was self-tested with stub binaries. The first real Hive run is still to come.</li>
<li><strong>A signed binary.</strong> Releases are signed by the project's release key, which the app checks. They do not yet carry a Developer ID or Authenticode signature, so the first install asks you to allow the app.</li>
</ul>
</section>
<section id="wallet">
<h2>The wallet</h2>
<p class="lead">Igneum Wallet is a desktop wallet, macOS first. It holds the key, signs, reads your own node, and checks finality with the node's own code.</p>
<div class="tbl"><table>
<thead><tr><th>Feature</th><th>What happens</th></tr></thead>
<tbody>
<tr><td>Create or import</td><td>24 words on the Ethereum derivation path, so the same words open the same account in MetaMask. Or import the raw key Ember made for you</td></tr>
<tr><td>The vault</td><td>The key is sealed on your disk with XChaCha20-Poly1305 under a key derived from your password by Argon2id (64 MiB, 3 passes). The password is never written anywhere. Nothing leaves the machine</td></tr>
<tr><td>Send</td><td>The fee is shown before you confirm</td></tr>
<tr><td>Receive</td><td>A QR code drawn on your machine, with no image service and no call across the network</td></tr>
<tr><td>History</td><td>Block rewards, proving payouts and transfers in one list</td></tr>
<tr><td>Final means final</td><td>The wallet fetches the finality certificate from the blocks that carried it and verifies the BLS signatures itself with the node's own finality code. Every entry shows pending, in a block, or final with its checkpoint index. A failed execution is never shown as final</td></tr>
<tr><td>MetaMask</td><td>The network parameters export in one click</td></tr>
<tr><td>Your node</td><td>The wallet reads Ember's node on this machine when it is there, so nobody else sees your balance. Without it, a public endpoint serves balances and sending, and a bundled node can be started by the wallet. Finality is verified only against a node's own interface; on a public endpoint entries stay "in a block"</td></tr>
<tr><td>Updates</td><td>Signed over-the-air updates, installed by themselves when no send is in flight, with rollback when the new version does not start</td></tr>
<tr><td>Next</td><td>Touch ID and Windows Hello to unlock. In progress, not live. Windows build: next</td></tr>
</tbody>
</table></div>
<p class="src"><b>Source:</b> Igneum Wallet, first shipped 5 October 2026, on the downloads host (the wallet source: the vault, HD key, finality, QR and updater modules and the README). Verified: the over-the-air path end to end on one Mac against a test manifest. Not yet run: the Windows path, the rollback paths, a Developer ID signature.</p>
</section>
<section id="governance">
<h2>Governance</h2>
<p>Igneum is governed by the hashrate that powers it. Today, as built, pools carry their hashers' votes, so pool concentration is the governance risk, and it is public: on the devnet the top three vote keys held 34.5% of 8,090 blocks on 4 October 2026, measured.</p>
<ul>
<li><strong>Nothing needs a scheduled upgrade.</strong> The mining program, the dataset and the finality rules run themselves for ever. If the community ever ships an improvement, a better proof system or a block-rate step, it is published with test vectors at least three months ahead and activates only when 90% of blocks signal readiness. Developers can write code. Only miners can turn it on.</li>
<li><strong>Miners set what genesis leaves open.</strong> Miners signal three things at three thresholds: 60 percent of blue blocks over two weeks for a parameter genesis leaves open, 90 percent for an upgrade (new code), and 95 percent with a floor height for a class change. There is no fund to vote on and no fee to any team, foundation or fund.</li>
<li><strong>Pools can be bypassed on transaction choice.</strong> Igneum ships Stratum v2 job declaration from day one, so a miner chooses its own transactions when its pool supports it. Pools can decline. Designed: the pool protocol is specification section 9, not yet run by any pool. Vote keys stay with the miner at protocol level: the member's retained voting key is committed into its work, payment aggregation is separate and verifiable, and pool identity substitution is resisted (a pin of Igneum 2.0, pools and participation; not yet shipped).</li>
<li><strong>There are no admin keys in consensus.</strong> Nothing in consensus can be paused, upgraded or reversed by any key. There is no foundation allocation to vote with and no stake to buy. The genesis apps are contracts, and each publishes its own upgrade and key policy before launch; the bridge's is the one to read. Designed, open item O-5.4. On the devnet the activation heights and one execution-state restart (6 October 2026) reach every node through the signed update manifest, so on the devnet the release key acts as the operator; the sentence above holds for mainnet consensus only once that path is closed, and the network's terms will say which parameters still travel that way.</li>
<li><strong>The chain runs without its founders.</strong> Blocks, proofs and finality need no one. A second independent node client is the first priority after launch, and anyone can build it.</li>
</ul>
</section>
<section id="roadmap">
<h2>Roadmap</h2>
<p>Six phases from specification to a fair launch, with four public gates and no calendar dates: each phase closes at its gate. Each gate is a measurement published whether it passes or fails. Miss it and the phase repeats or the project stops. Each piece of Igneum has a precedent in production somewhere; no chain combines them, and the combination is the risk the gates price.</p>
<div class="tbl"><table>
<thead><tr><th>Phase</th><th>When</th><th>What</th><th>Gate to pass</th></tr></thead>
<tbody>
<tr><td>1. Specification</td><td class="num">Under way; closes when the specification is out for external review</td><td>Mining generator, shard proving, finality rules, written for external review</td><td></td></tr>
<tr><td>2. Prove the proving</td><td class="num">Under way; closes at its gate</td><td>Mining program prototype on GPU and CPU, shard proving benchmark on consumer cards. So far: an RTX 5090 proves a shard in 10.9 s compressed; a CPU verifies a warp in 0.61 ms (class v2) to 2.1 ms (class v3). A mid-range card has not been measured</td><td>A mid-range GPU proves a shard in under 20 s and a CPU verifies a hash in 10 ms</td></tr>
<tr><td>3. Devnet</td><td class="num">Under way; closes at its gate</td><td>BlockDAG node with the new mining program and EVM execution, every upgrade on from block zero: class v4, the era VDF, difficulty v2, finality v3, proving v0 and v1, the ladder at rung 0, calibrated fees, Ember on every machine. The devnet's proof lag and proven share are read from the observer as the fleet publishes them</td><td>1 block a second held with proofs under 60 s behind the tip</td></tr>
<tr><td>4. Finality and job market</td><td class="num">Closes when the finality design passes external review and one external customer pays for repeat proving jobs</td><td>Sustained-mining finality, external proving jobs, miner client with auto-switching</td><td>Finality design passes external review and one external customer pays for repeat jobs of its exact workload</td></tr>
<tr><td>5. No-rescue network exercise</td><td class="num">Open; its prerequisite, proof verification enforced in consensus, is on from block zero on the 2.0 devnet</td><td>No founder-operated mining, proving, aggregation or distribution. Epoch boundaries crossed, signing interrupted, the network partitioned, major operators removed, hostile proof submissions, independently written clients, a withholding prover replaced. One-click miner, HiveOS, pools, no coin yet</td><td>Specified behaviour with no emergency algorithm change and no privileged intervention; 1,000 independent miners run 30 days</td></tr>
<tr><td>6. Mainnet fair launch</td><td class="num">After phase 5 has passed its gate</td><td>Genesis with no premine, 30-day ramp. No listing is arranged, promised or sought by the project</td><td></td></tr>
</tbody>
</table></div>
<p>Dates slip. Gates do not. Phase two decides everything. If consumer GPUs cannot prove shards fast enough, Igneum says so and does not launch on promises.</p>
<h3>The five deliverables of Igneum 2.0</h3>
<div class="tbl"><table><thead><tr><th>Deliverable</th><th>Owner</th><th>Pass condition</th><th>Today</th><th>Evidence</th></tr></thead><tbody>
<tr><td>D1. A frozen, reproducible baseline</td><td>the coordinator with the hash and node lanes</td><td>an independent operator reproduces the baseline within declared tolerances from the served kit alone</td><td>PENDING: the kit is pinned by digest (the release manifest); the reference GPU population, the two tests per class and the cost per accepted unit of work are owed</td><td><a href="https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/plans/igneum-2.0.md">igneum-2.0.md</a></td></tr>
<tr><td>D2. Two architectural experiments</td><td>the class v6 invention lane (a), the multi-family adversary lane (b)</td><td>the candidate improves against re-optimised adversaries within the preset cost and verification limits, or v6 stands and the experiment is published as a failure</td><td>(a) TEAM-REPORTED, killed as a class: only the window width reaches the chip; (b) open</td><td><a href="https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/analysis/class-v6/connected-state.md">connected-state.md</a></td></tr>
<tr><td>D3. A programmable adversary allowed to survive</td><td>the multi-family adversary lane with the k lane</td><td>the best supported cost and energy advantage sits inside the chosen competitiveness envelope, with uncertainty published</td><td>MODELLED: the placed and routed core energies served above; the dataset schedule and the state coupling are under evaluation</td><td><a href="https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/design/class-v6-rotating-family.md">class-v6-rotating-family.md</a></td></tr>
<tr><td>D4. A five-year coexistence model</td><td>the research lane with the k lane’s rows</td><td>the model names credible conditions for sustained commodity participation and names where it fails</td><td>MODELLED, first run served: the DRAM board passes six of seven conditions; the die fails on its machine cost; the thresholds live in the sensitivity workbook</td><td><a href="https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/analysis/class-v6/coexistence-model.md">coexistence-model.md</a></td></tr>
<tr><td>D5. A no-rescue network exercise</td><td>the node lane with the build-server lane</td><td>specified behaviour with no emergency algorithm change and no privileged intervention</td><td>PENDING: the prerequisite (proof verification enforced in consensus) is on from block zero on the Igneum 2.0 devnet; the exercise itself is owed</td><td><a href="https://git.igneum.network/igneum-network/igneum/src/branch/master/docs/spec/finality-guarantees.md">finality-guarantees.md</a></td></tr>
</tbody></table></div>
<p class="src">The pins and their pass conditions are <code>docs/plans/igneum-2.0.md</code>; the Today column carries the served labels (TEAM-REPORTED, MODELLED, PROPOSED, PENDING, EXCLUDED) and moves only with a landed document. The <a href="/scorecard">acceptance scorecard</a> is the checklist across the twelve gates.</p>
</section>
<section id="miners-ask">
<h2>Questions miners ask</h2>
<h3>Kaspa was GPU-mined too, and IceRiver shipped a chip within two years.</h3>
<p>Kaspa never promised chip resistance, and its hash was one fixed function, simple enough to put on silicon. Igneum does not claim a chip cannot be built. It assumes one exists and scores it: the chip model states the energy advantage, the economic advantage and the response capability separately. The public benchmark with a leaderboard is owed work, and so is the comparison against operating GPU networks: Ravencoin's KAWPOW, Ergo and Firo's reference miner. No result exists yet. The in-house adversarial pass and the public benchmark are where a stronger chip design would show. And if a chip ever appears, miners are the ones who signal the response.</p>
<h3>Don't ASICs make a chain safer?</h3>
<p>Three parts. First, what the chain asks hash to do. Hash picks who makes the next block. It does not protect history. A checkpoint locks when signatures reach two thirds of the weight of the last 30 days of blocks (specification section 3). A locked checkpoint is never reorganised by any amount of hash: fork choice runs among the tips that pass through every certified checkpoint. Rented hash has no weight today. It can mine blocks. It cannot rewrite anything older than a lock. A renter with 60% of the network holds 0.0% of the vote on day one (the finality simulator, table B); one matching the whole honest network reaches a third of the weight on day 20 and never two thirds. The lock is fast: median 1,018 ms behind the checkpoint on the three-node test network (engineering log, the finality harness), and with a two-hour window the first lock came two hours after genesis, once the window was full. Reorganisations under the lock are shallow: at 1, 2 and 5 blocks a second the deepest honest reorganisation measured was 2, 3 and 7 blocks against a determination depth of 20 (ledger F7, round 2, the fast-time network with 100-ms links); across five continents blocks reached every node at p50 343 ms and p99 666 ms (the 12-node cloud network, 4 October 2026).</p>
<p>Second, the cost the ASIC argument skips. Kaspa's hash went to a handful of chip owners within months: the IceRiver KS0 shipped in July 2023, 17 to 20 months after launch; hashrate went from under 100 PH/s to over 700 PH/s in months and the GPU share was negligible by late 2023 (the ASIC history, row 23, approximate for the share). Bitcoin's hash comes from two manufacturers and a few pools (approximate, from memory). The first chip's owner mines in secret with an edge for months: on Monero, 85% of the hashrate vanished at the April 2018 fork, and chips were found at over 85% again four months after the next fork (row 16). A chip does not add security to a chain; it moves the chain's security to whoever owns the chip first.</p>
<p>Third, the honest part. A young GPU chain's hash is cheap to rent, and we publish the number beside the chain's own. The locks are what make that rental unable to buy a double-spend: a deposit under a lock stays, whatever the renter mines on top. Ethereum Classic (January 2019 and August 2020), Bitcoin Gold (May 2018 and January 2020) and Vertcoin (October to December 2018, December 2019) were reorganised with rented hash (the ASIC history rows 6 and 7 for Bitcoin Gold and Vertcoin; the Ethereum Classic dates approximate, from memory); Verge's 2018 reorganisations used a timestamp flaw in its multi-algorithm rule as well as hash (approximate). On those chains the rented hash rewrote history because nothing but hash held it. Here the same rental mines blocks for its hour and leaves the locks where they were. The exception is stated above: in the first 30 days of mainnet no checkpoint locks, the chain is plain proof of work with a 12-hour depth, and a rental can reorganise inside that depth; anyone crediting deposits in that month treats it so.</p>
<div class="tbl"><table>
<thead><tr><th>What</th><th>Number</th><th>Source</th></tr></thead>
<tbody>
<tr><td>Rented NVIDIA hash, 6 October 2026</td><td class="num">2 GH/s for USD 13 an hour</td><td>The rental order for the rented cards of 6 October 2026, approximate; the fleet's bench entry is not yet written</td></tr>
<tr><td>The devnet's hash the same afternoon</td><td class="num">282 MH/s</td><td>the public stats API, 6 October 2026, 16:40 UTC; 181 MH/s an hour earlier with one PC off; 2.66 GH/s at 18:16 UTC with the rented cards mining</td></tr>
<tr><td>Weight a renter holds on day one</td><td class="num">0.0%</td><td>The finality simulator, table B (ledger M12)</td></tr>
<tr><td>Lock latency behind the checkpoint</td><td class="num">1,018 ms median</td><td>Engineering log, the finality harness, three nodes</td></tr>
<tr><td>A 50-miner wave against the devnet: blocks taken, locks moved</td><td class="num">not yet measured</td><td>Owed to the fleet's bench entry; the rented cards joined on 6 October 2026</td></tr>
</tbody>
</table></div>
<h3>Finality weighted by mining history is new. New gets attacked.</h3>
<p>Correct, and it is the first thing the external review will be paid to break. The specification is public; reviewers will be named and paid before gate 3, and the public benchmark carries the metrics they test against. Until then every finality claim here is a design claim backed by simulations and by the devnet, and the chain runs on plain GHOSTDAG without the rule, so it can be fixed without stopping the chain.</p>
<h3>Who are you?</h3>
<p>One founder, pseudonymous, working with AI systems. The design, the hostile reviews, the code, the simulators and this document were produced that way, and the commit history says so. The software is shipped by Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre. The design remains the work of one founder working with AI systems, reviewed in public through the ledger. What that does and does not mean: the measurements are measurements, reproducible from the commands in the engineering log; the simulators are code anyone can run; the design claims stay design claims until people with names have tried to break them. Every criticism the project expects is kept in a ledger with its honest answer, and the entries that were right are marked conceded; the ledger is public at /ledger. No cryptographer is hired yet; the plan budgets one for phases 1 and 2, and external reviewers are named and paid before gate 3.</p>
<p>The founders mine from genesis with disclosed addresses and the same software as everyone else, and hold no coins before block one. The team is pseudonymous and there is no team page. The mining addresses are published before launch; the code history is published with the repository.</p>
<h3>Where is the miner?</h3>
<p>On the devnet now. Igneum Ember runs on Windows, macOS and Linux, a HiveOS package exists, and the devnet's coins have no value. The public benchmark with a leaderboard and the pools are owed before launch. All of it before any coin exists. Nothing is asked of a miner before they can run something. The <a href="#ember">Ember section</a> says what is shipped and what is still owed.</p>
<h3>Will my card still pay in a bear market?</h3>
<p>Block reward and in-chain proving move with the price. Proving for other chains is priced in the customer's money, and it is a small market today. What Igneum can promise is that its miners' electricity cost in that market is close to power, because the card is already running on domestic power; the price they must charge is the subsidy they forgo, which falls as one over network hash. That is an edge over data-centre provers at scale and nothing more.</p>
</section>
<section id="builders-ask">
<h2>Questions builders ask</h2>
<h3>Proof of work, in 2027?</h3>
<p>Igneum's miners are paid for proving, not only for hashing, so the energy buys a proof of every block as well as the ordering of it. Proof of work also gives what stake cannot: no stake to capture, no builder cartel between you and the block, no foundation that can change the rules, and a chain whose state is proven at the base layer, which Ethereum does not have today.</p>
<h3>What does a one-minute proof mean for my app?</h3>
<p>Nothing you wait for. Your transaction executes in about a second. A miner lock arrives in about two minutes and that is the finality your contract sees. The proof follows and makes the state unforgeable. Liquidations and trades act on executed state at once, as on any chain. A bridge built on Igneum waits for the lock, about two minutes.</p>
<h3>Which stablecoin, and is there liquidity?</h3>
<p>None is bridged at genesis, and no bridge is official. The project will ask Circle for native USDC before launch; whether it is issued is Circle's decision. Anyone may run a bridge at their own risk until the proof bridge arrives with the consensus proof in phase two. The DEX is seeded at launch by the founders' own mined coins and by miners, and every miner is a funded wallet.</p>
<h3>What do I get for being early?</h3>
<p>20% of the priority fee on every transaction that runs your code, paid to you every block, which at launch fee levels is small and stated as such above. A place in the wallet's Apps tab and the explorer from day one. First access to the proving precompile and the job market. And a user base that was not paid to arrive: the miners.</p>
<h3>How do I deploy?</h3>
<p>Point Hardhat or Foundry at an Igneum node with the chain id and deploy the same bytecode. Verify the source in the explorer. Register a developer address for the gas share. The afternoon is the hard part.</p>
</section>
<section id="shoulders">
<h2>Built on the shoulders</h2>
<p>Every borrowed part of Igneum is credited here, in public. The rule, decided on 3 October 2026: credit every component, replace only what the design requires, and measure every change. Nothing was taken quietly.</p>
<ul>
<li><strong>Kaspa, rusty-kaspa (ISC).</strong> The GHOSTDAG ordering and the node Igneum is forked from, at v2.1.0; the sampled difficulty rule is kept as the retarget; the block-rate step plan follows Kaspa's own rise (approximate).</li>
<li><strong>Monero, RandomX by tevador (BSD).</strong> The random-program idea and the small-cache, large-dataset design, rebuilt for GPUs with a program per hour instead of a program per hash.</li>
<li><strong>ProgPoW and Ravencoin's KAWPOW.</strong> The first GPU randomisation precedents; they randomised the maths inside a fixed shape, Igneum regenerates the whole program. Cited from memory until their repositories are cloned beside the others, approximate.</li>
<li><strong>LWMA by Zawy and Monero's trimmed window.</strong> Difficulty precedents studied for the hourly hash-speed step; no code taken.</li>
<li><strong>Chia, chiavdf (Apache 2.0) and Wesolowski's proof.</strong> The class-group delay between a locked checkpoint and the next program seed, ported into the prototype.</li>
<li><strong>Ethereum.</strong> The virtual machine itself, run through revm (MIT), with its semantics restated for a DAG.</li>
<li><strong>Succinct, SP1 (MIT or Apache 2.0).</strong> The first proof system behind Igneum's versioned proving interface; any hash-based prover can replace it by a miner-signalled release.</li>
<li><strong>BLS12-381 through blst (Apache 2.0).</strong> The vote-key signatures on every 30-second checkpoint.</li>
<li><strong>Bitcoin's bech32 and Bitcoin Cash's CashAddr checksum.</strong> The address format, through Kaspa, with Igneum prefixes.</li>
<li><strong>BLAKE2b, BLAKE3, SHA-256, Keccak.</strong> The hashes the node already uses, unchanged. ChaCha, SplitMix64 and FNV-1a inside the lottery hash, implemented from their definitions.</li>
</ul>
<p>What is Igneum's own: the hourly header-bound GPU program, the sustained-mining finality rule, two-dimensional gas with the per-frame app share, the shard market and proving precompile, and the automatic era draws. The full table, with what changed in each component, why the design needed it, and the measurement or specification section that covers it, is the provenance page, rendered from the repository's provenance document. Licences stated from memory are marked approximate there and are verified as each clone lands.</p>
</section>
<section id="limits">
<h2>What Igneum does not claim</h2>
<p>Here are the limits, stated before anyone else states them.</p>
<ul>
<li><strong>A proof in seconds.</strong> Not at launch. Proving a full block today needs a cluster of 100 to 200 consumer GPUs, approximate, so Igneum launches with proofs within about a minute and tightens as hardware improves. Users still see their transaction land in one second.</li>
<li><strong>A chip is impossible.</strong> No. Igneum assumes a chip exists. A programmable chip is not stopped by the moving target: everything it needs is public at genesis and every drawn parameter is firmware to it (an address permute, a rotator, an immediate table), so the defence against it is the latency-shadow work (class v4) and the price per joule, not the schedule (the chip and economy analysis of 6 October 2026, section 5.4; ledger M32). Igneum remains competitive on accessible commodity GPUs even when specialised mining hardware is assumed to exist, remain compatible and seek profit; its security does not rely on identifying that hardware or retiring it through emergency changes. Class v6 adopts the 64-register window and retains it across every rotation. Current modelling estimates a 1.5x to 3.1x energy-efficiency advantage for the specialised designs assessed as complete machines against the GPU tier, from a board on commodity DRAM at 1.5x to an SRAM-store die at 3.1x (1.5x to 2.3x on the GPU's own node). The long-program and select-tree proposals were rejected. Economic resistance depends on development cost, deployment economics and productive hardware lifetime; family transitions receive an obsolescence benefit only where a loss of competitiveness is demonstrated; programmable multi-epoch designs are included in the assessment. The labels: the bracket modelled, approximate and provisional (the GPU side measured on the RTX 5080 and RTX 5090 at their core locks under class v4, 8 October 2026; the chip core synthesised on ASAP7 and scaled to N3, claimed, its placed gated row pending; its memory modelled). Class v5 makes the dataset the chain’s own state, so a chip that stores it or recomputes it is wrong on every item (designed, 7 October 2026; under evaluation (Deliverable 3), not counted as a defence until justified or dropped). The strongest recompute chip we can price, holding the whole 256 MiB cache on-die, reaches under 1x per chip against an RTX 5090 (the published model, 5 October 2026: 0.92x per unit of silicon with a 3x fixed-function allowance, approximate). Sources: the class v6 close, section 10 (8 October 2026); the ASIC history’s Ethash rows; the chip model analysis (6 October 2026). No hash has stayed free of chips forever; Igneum does not claim to. Monero’s RandomX has held its miners on commodity hardware for about seven years: one chip shipped against it, Bitmain’s Antminer X5 (September 2023), an observed comparison, not a ceiling; the one announced beyond it, the Antminer X9, was withdrawn in mid-May 2026 before any unit shipped, its claimed core never measured; RandomX v2 was released on 25 March 2026 with its activation pending. That record says nothing about the price of a chip with the 256 MB cache on its die; that price is a cost model, not a measurement.</li>
<li><strong>A guaranteed income floor.</strong> No. External proving is a small market today. Igneum's miners' electricity cost in it is close to power, but the price they must charge is the subsidy they forgo, which falls as one over network hash: an edge at scale and nothing more.</li>
<li><strong>A memory-hard prototype on every vendor.</strong> Not yet. The 256 MB cache closed the shortcut on Apple silicon (computing items runs 4.8x slower than loading them, measured 3 October 2026). The same ratio on NVIDIA and on a discrete AMD card is Open.</li>
<li><strong>Finality in the first month.</strong> No. No checkpoint locks until the 30-day window has 30 days of history. The first month of mainnet is proof of work with a 12-hour depth, and the text above says so wherever a day count appears.</li>
<li><strong>A cryptography team.</strong> Not yet. One founder working with AI systems wrote the design and the code; external reviewers are named and paid before gate 3, and every security claim here is a design claim until then.</li>
<li><strong>Finality that no amount of hardware can break.</strong> No. A miner holding a third of the last 30 days of blocks can split finality during a network partition, and two thirds can lock a bad checkpoint for a double-spend bounded by the 12-hour finality depth. Reaching a third takes at least ten days of producing every block on the chain, in public; an attacker matching the honest network needs twenty days for a third and never reaches two thirds. That is harder than attacking Bitcoin, where a majority can reorganise at once, and it is the limit of proof of work without stake or an outside chain. Igneum chose those limits on purpose. The floor is also bounded in time: an honest partition that lasts long enough for each side's own new blocks to reach two thirds of its window locks on both sides, about ten days of a 30-day window at an even split, and an operator must then resolve it (measured on a test network, 4 October 2026).</li>
<li><strong>Finality that never pauses.</strong> No. A lock needs two thirds of all 30-day mining weight. Whenever less than two thirds of that weight is connected and signing, finality pauses until it returns or ages out of the window, up to 30 days. The chain keeps running on proof of work and the node reports the pause.</li>
<li><strong>A label that costs nothing.</strong> No. Some investors and exchanges read "GPU-mined" as 2021 whatever the proofs do, and nothing here measures that cost. The only evidence will be whether the first miner apps and verifiable-compute apps sign despite the label.</li>
<li><strong>A chain you can debug today.</strong> Not yet. The node does not serve debug_traceTransaction, eth_subscribe or eth_getProof. The explorer, the faucet and the reference apps run on the devnet; the tracing and subscription RPCs are still owed.</li>
<li><strong>A veto on job results.</strong> No. A segment proof is checked against every node's own execution; a proving job for another chain is not, because no full node can re-run an arbitrary program, so a soundness bug in the proof system in force reaches the requesting contract. A job output can mint nothing and touch no system contract, and an app that acts irreversibly on a job result keeps its own fallback.</li>
<li><strong>A delay function that outlives a quantum computer.</strong> No. The class-group delay between a locked checkpoint and the next program seed falls to the same machine that would forge the vote keys; it is flagged in the specification, not yet sized, and the fallback is a hash-chain delay behind the same version byte that moves the signature scheme, so both flip in one class change. A grindable hourly seed is a liveness nuisance against the lottery, not a break of finality.</li>
<li><strong>Proof verification in consensus.</strong> On the Igneum 2.0 devnet, yes, from block zero (verifier_in_consensus set, the node's own start line; running since its first block at 17:14 UK on 8 October 2026). It is the prerequisite of the no-rescue network exercise (Deliverable 5), which is still owed; an earlier devnet ran with the rule off.</li>
<li><strong>Proving on every card.</strong> No. NVIDIA proves; AMD and Apple mine. The proving stack is judged on the full pipeline: inputs, proving, aggregation, verification, payment, memory and the mining income forgone.</li>
<li><strong>What proofs do not give.</strong> Proven execution is not finality. EVM compatibility is not Ethereum security. ZK is not privacy.</li>
<li><strong>A ranking.</strong> No. Igneum makes no leading or number-one claim. Benchmarks against Ravencoin's KAWPOW, Ergo and Firo's reference miner are owed work; no result exists yet.</li>
<li><strong>A finished protocol.</strong> The sustained-mining finality rule is the newest piece and the one that external review will try hardest to break. The specification, the review and the benchmarks are published as they happen.</li>
</ul>
<p>Everything in this document is subject to the gates on the roadmap. Nothing in it is an offer to sell anything. Found an error, or a criticism this document does not answer? Email <a href="mailto:hello@igneum.network">hello@igneum.network</a>, or open an issue on the public specification repository: <a href="https://git.igneum.network/igneum-network/spec/issues" rel="noopener">git.igneum.network/igneum-network/spec/issues</a>. Post reaches Igneum Labs LTD, Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre.</p>
</section>
</article>
</div>
</main>
<!-- footer:start -->
<footer class="site-footer">
<div class="container">
<p class="positioning">A GPU-secured network for Ethereum-compatible applications and verifiable computation.</p>
<div class="footer-grid">
<div class="footer-brand">
<a href="/" class="logo" aria-label="Igneum home"><svg class="brand-mark" viewBox="0 0 1024 1024" aria-hidden="true"><rect width="1024" height="1024" rx="160" fill="#0C0C0E"></rect><g transform="translate(166.95 166.95) scale(6.901)"><polygon points="50,4 74,34 67,58 80,54 61,96 39,96 20,54 33,58 26,34" fill="#F2541B"></polygon><polygon points="50,42 59,58 50,82 41,58" fill="#0C0C0E"></polygon></g></svg><span class="word">IGNEUM</span><span class="stop">.</span></a>
<p>Mined by GPUs. Proven by fire.</p>
<div class="social" aria-label="Igneum elsewhere">
<a href="https://git.igneum.network/igneum-network/spec" target="_blank" rel="noopener" aria-label="Igneum source: the spec, the vectors and the issues"><svg viewBox="0 0 24 24" width="22" height="22" fill="currentColor" aria-hidden="true"><path d="M8.6 17.6 3 12l5.6-5.6 1.4 1.4L5.8 12l4.2 4.2zm6.8 0-1.4-1.4L18.2 12 14 7.8l1.4-1.4L21 12z"></path></svg></a>
<a href="https://discord.gg/igneum" target="_blank" rel="noopener" aria-label="The Igneum Discord"><svg viewBox="0 0 24 24" width="22" height="22" fill="currentColor" aria-hidden="true"><path d="M19.6 5.3A17 17 0 0 0 15.4 4l-.2.4a15.6 15.6 0 0 1 3.9 1.9 13.6 13.6 0 0 0-14.2 0A15.6 15.6 0 0 1 8.8 4.4L8.6 4a17 17 0 0 0-4.2 1.3C1.8 9.2 1.1 13 1.4 16.7a17.1 17.1 0 0 0 5.2 2.6l1.1-1.8a10.8 10.8 0 0 1-1.7-.8l.4-.3a12.2 12.2 0 0 0 11.2 0l.4.3-1.7.8 1.1 1.8a17 17 0 0 0 5.2-2.6c.4-4.3-.7-8-3-11.4zM8.7 14.4c-1 0-1.8-.9-1.8-2.1s.8-2.1 1.8-2.1 1.9 1 1.8 2.1c0 1.2-.8 2.1-1.8 2.1zm6.6 0c-1 0-1.8-.9-1.8-2.1s.8-2.1 1.8-2.1 1.9 1 1.8 2.1c0 1.2-.8 2.1-1.8 2.1z"></path></svg></a>
<a data-social="reddit" href="https://www.reddit.com/user/Igneum_network/" target="_blank" rel="noopener" aria-label="Igneum on Reddit"><svg viewBox="0 0 24 24" width="22" height="22" fill="currentColor" aria-hidden="true"><path d="M22 12.1a2.2 2.2 0 0 0-3.7-1.6 10.8 10.8 0 0 0-5.8-1.8l1-4.6 3.2.7a1.5 1.5 0 1 0 .2-.9l-3.6-.8a.5.5 0 0 0-.5.4l-1.1 5.2a10.8 10.8 0 0 0-5.9 1.8A2.2 2.2 0 1 0 3.4 14a4.3 4.3 0 0 0 0 .7c0 3.4 3.9 6.1 8.6 6.1s8.6-2.7 8.6-6.1a4.3 4.3 0 0 0 0-.7 2.2 2.2 0 0 0 1.4-1.9zM7 13.6a1.5 1.5 0 1 1 1.5 1.5A1.5 1.5 0 0 1 7 13.6zm8.6 4.1a5.7 5.7 0 0 1-3.6 1.1 5.7 5.7 0 0 1-3.6-1.1.4.4 0 0 1 .6-.6 4.9 4.9 0 0 0 3 .9 4.9 4.9 0 0 0 3-.9.4.4 0 0 1 .6.6zm-.3-2.6a1.5 1.5 0 1 1 1.5-1.5 1.5 1.5 0 0 1-1.5 1.5z"></path></svg></a>
</div>
<div class="footer-dl" aria-label="Download Ember"><a href="/download#windows"><span class="osmark mini" data-os="windows" title="Windows"><svg viewBox="0 0 24 24" width="22" height="22" aria-hidden="true" focusable="false" fill="currentColor"><path d="M3 5.6l7.3-1v7.1H3zM11.4 4.4L21 3v8.7h-9.6zM3 12.3h7.3v7.1L3 18.4zM11.4 12.3H21V21l-9.6-1.4z"/></svg></span>Windows</a><a href="/download#mac"><span class="osmark mini" data-os="mac" title="macOS"><svg viewBox="0 0 24 24" width="22" height="22" aria-hidden="true" focusable="false" fill="currentColor"><path d="M16.4 12.6c0-2.5 2-3.6 2.1-3.7-1.2-1.7-3-1.9-3.6-2-1.5-.2-3 .9-3.8.9-.8 0-2-.9-3.3-.8-1.7 0-3.2 1-4.1 2.5-1.8 3-.5 7.6 1.3 10.1.9 1.2 1.9 2.6 3.2 2.5 1.3 0 1.8-.8 3.3-.8 1.6 0 2 .8 3.3.8 1.4 0 2.3-1.2 3.1-2.5 1-1.4 1.4-2.8 1.4-2.9 0 0-2.7-1-2.9-4.1zM13.9 5.3c.7-.8 1.2-2 1-3.2-1 0-2.2.7-2.9 1.5-.6.7-1.2 1.9-1 3 1.1.1 2.2-.5 2.9-1.3z"/></svg></span>macOS</a><a href="/download#linux"><span class="osmark mini" data-os="linux" title="Linux"><svg viewBox="0 0 24 24" width="22" height="22" aria-hidden="true" focusable="false" fill="currentColor"><path d="M12 2c-2.4 0-4 1.9-4 4.6 0 1.2.2 2 0 2.8-.6 1.4-2.1 2.9-2.6 4.9-.3 1.1-.1 2 .3 2.6-.6.4-1.3 1-1.1 1.7.3 1 2.1 1.2 3.2 1.8.7.4 1.5.6 2.1.1.6.2 1.3.3 2.1.3s1.5-.1 2.1-.3c.6.5 1.4.3 2.1-.1 1.1-.6 2.9-.8 3.2-1.8.2-.7-.5-1.3-1.1-1.7.4-.6.6-1.5.3-2.6-.5-2-2-3.5-2.6-4.9-.2-.8 0-1.6 0-2.8C16 3.9 14.4 2 12 2zm-1.4 4.2c.5 0 .8.5.8 1.2s-.3 1.2-.8 1.2-.8-.5-.8-1.2.3-1.2.8-1.2zm2.8 0c.5 0 .8.5.8 1.2s-.3 1.2-.8 1.2-.8-.5-.8-1.2.3-1.2.8-1.2zM12 9.3c.9 0 1.9.5 1.9 1s-1 1.2-1.9 1.2-1.9-.7-1.9-1.2 1-1 1.9-1zm0 3.4c2.2 0 3.6 2.6 3.6 4.4 0 1.5-1.6 2.3-3.6 2.3s-3.6-.8-3.6-2.3c0-1.8 1.4-4.4 3.6-4.4z"/></svg></span>Linux</a><a href="/download#hive"><span class="osmark mini" data-os="hive" title="HiveOS"><svg viewBox="0 0 24 24" width="22" height="22" aria-hidden="true" focusable="false" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linejoin="round" stroke-linecap="round"><path d="M12 2.6 20.2 7.3v9.4L12 21.4 3.8 16.7V7.3z"/><path d="M12 7.4 16 9.7v4.6L12 16.6 8 14.3V9.7z"/><path d="M12 7.4V2.6M16 9.7l4.2-2.4M16 14.3l4.2 2.4M12 16.6v4.8M8 14.3l-4.2 2.4M8 9.7 3.8 7.3"/></svg></span>HiveOS</a></div>
<a href="https://git.igneum.network/igneum-network/spec" target="_blank" rel="noopener" class="text-link">Specification and test vectors<svg class="icon" viewBox="0 0 24 24" aria-hidden="true"><path d="M6 18 18 6M6 6h12v12"/></svg></a>
</div>
<div class="footer-column"><h4>Run</h4><div>
<a href="/download">Download Ember</a>
<a href="/miner">The miner</a>
<a href="/app">The app</a>
<a href="/wallet">The wallet</a>
<a href="/miners">GPU bench table</a>
<a href="/dev-fee">The dev fee</a>
<a href="/faucet">Devnet faucet</a>
<a href="/metamask">Add Igneum to MetaMask</a>
</div></div>
<div class="footer-column"><h4>Read</h4><div>
<a href="/litepaper">Litepaper</a>
<a href="/evidence">Evidence</a>
<a href="/ledger">Ledger: every criticism</a>
<a href="/claims">What Igneum does not claim</a>
<a href="/randomx">Igneum vs RandomX</a>
<a href="/provenance">Built on the shoulders</a>
</div></div>
<div class="footer-column"><h4>Explore</h4><div>
<a href="/live">Live devnet</a>
<a href="/explorer">Explorer</a>
<a href="/build">Build on Igneum</a>
<a href="/swap">Swap</a>
<a href="/grants">Grants</a>
<a href="/download">Downloads: devnet build</a>
<a href="https://discord.gg/igneum" target="_blank" rel="noopener">Community Discord</a>
<a href="mailto:hello@igneum.network">hello@igneum.network</a>
<a href="https://git.igneum.network/igneum-network/spec/issues" rel="noopener">An issue on the spec</a>
</div></div>
</div>
<div class="footer-bottom">
<p>Igneum Labs LTD · Unit IH-00-01-01-OF-01, Level 01, Innovation One, Dubai International Financial Centre. Experimental software. Nothing on this site is an offer to sell anything.<br>Report a flaw by email or by an issue on the spec. Nobody from Igneum will ask for your seed. © 2026 Igneum · not an offer to sell anything</p>
<div class="theme-group" role="group" aria-label="Theme"><button type="button" data-theme-set="system" aria-pressed="true">System</button><button type="button" data-theme-set="light" aria-pressed="false">Light</button><button type="button" data-theme-set="dark" aria-pressed="false">Dark</button></div>
</div>
</div>
</footer>
<script>
(function(){
// theme control: stores light or dark under igneum-theme; system clears it and follows the OS. The head applied the value before paint.
var bs=document.querySelectorAll('[data-theme-set]');if(!bs.length)return;
var media=window.matchMedia('(prefers-color-scheme: light)');
function stored(){try{var t=localStorage.getItem('igneum-theme');return t==='light'||t==='dark'?t:'system';}catch(e){return 'system';}}
function apply(){var c=stored();document.documentElement.setAttribute('data-theme',c==='system'?(media.matches?'light':'dark'):c);bs.forEach(function(b){b.setAttribute('aria-pressed',b.getAttribute('data-theme-set')===c?'true':'false');});document.dispatchEvent(new CustomEvent('igneum-theme'));}
bs.forEach(function(b){b.addEventListener('click',function(){var v=b.getAttribute('data-theme-set');try{if(v==='system')localStorage.removeItem('igneum-theme');else localStorage.setItem('igneum-theme',v);}catch(e){}apply();});});
if(media.addEventListener)media.addEventListener('change',function(){if(stored()==='system')apply();});
document.addEventListener('igneum-theme',function(){var c=stored();bs.forEach(function(b){b.setAttribute('aria-pressed',b.getAttribute('data-theme-set')===c?'true':'false');});});
bs.forEach(function(b){b.setAttribute('aria-pressed',b.getAttribute('data-theme-set')===stored()?'true':'false');});
// the network state word in the status bar: one read of the observer per page view
var fs=document.getElementById('foot-state'),fd=document.getElementById('foot-dot');if(fs&&fd&&fs.getAttribute('data-devnet-state')==='live'){fetch('/api/live?window=30',{cache:'no-store'}).then(function(r){return r.json();}).then(function(d){var on=d&&d.ok&&d.state&&!d.state.stale;fs.textContent=on?'devnet live':'devnet, observer stale';fd.className='dot '+(on?'live':'off');}).catch(function(){fs.textContent='devnet';});}
})();
</script>
<!-- footer:end -->
<script>
(function(){
// Section router. The URL hash names a section (or any heading inside one) in both reading modes. In-page links are
// routed here instead of the browser's own fragment jump: that jump cannot land on a hidden section, and in whole-paper
// mode it used to land and then be dragged back to the top of the article by a second scroll. Back and forward replay
// through popstate, every scroll clears the sticky bar (and the contents row on a phone), and focus moves to the
// heading so the keyboard and a screen reader continue from the section, not from the contents list.
var secs=Array.prototype.slice.call(document.querySelectorAll('article section'));
var toc=document.querySelector('.toc'),links=Array.prototype.slice.call(document.querySelectorAll('.toc ol a'));
var mAll=document.getElementById('m-all'),mTabs=document.getElementById('m-tabs');
var reduce=window.matchMedia('(prefers-reduced-motion: reduce)').matches;
var all=true;try{all=localStorage.getItem('lp-mode')!=='tabs';}catch(e){}
// every subsection heading gets an id from its text, so each one is reachable by URL
var used={};secs.forEach(function(s){used[s.id]=1;});
secs.forEach(function(s){Array.prototype.slice.call(s.querySelectorAll('h3')).forEach(function(h){if(h.id)return;
var base=h.textContent.toLowerCase().replace(/[^a-z0-9]+/g,'-').replace(/^-|-$/g,'').slice(0,60).replace(/-$/,''),id=base,n=2;
while(used[id])id=base+'-'+(n++);used[id]=1;h.id=id;});});
secs.forEach(function(s,i){
var pager=document.createElement('div');pager.className='pager';
if(i>0){var a=document.createElement('a');a.href='#'+secs[i-1].id;a.innerHTML='<span>previous</span> '+secs[i-1].querySelector('h2').textContent;pager.appendChild(a);}
if(i<secs.length-1){var b=document.createElement('a');b.href='#'+secs[i+1].id;b.className='next';b.innerHTML=secs[i+1].querySelector('h2').textContent+' <span>next</span>';pager.appendChild(b);}
s.appendChild(pager);
});
function target(hash){var id=(hash||'').replace(/^#/,'');if(!id)return null;var el=document.getElementById(id);if(!el)return null;var s=el.closest('article section');return s?{sec:s,el:el===s?null:el}:null;}
function offset(){var nav=parseFloat(getComputedStyle(document.documentElement).getPropertyValue('--nav-h'))||68;return nav+(window.innerWidth<960&&toc?toc.offsetHeight:0)+12;}
function measure(){document.documentElement.style.setProperty('--lp-off',offset()+'px');}
function go(hash,o){o=o||{};var t=target(hash)||{sec:secs[0],el:null};
secs.forEach(function(s){s.classList.toggle('active',s===t.sec);});
links.forEach(function(l){var on=l.getAttribute('href')==='#'+t.sec.id;l.classList.toggle('active',on);if(on)l.setAttribute('aria-current','true');else l.removeAttribute('aria-current');
if(on&&window.innerWidth<960&&l.scrollIntoView){try{l.scrollIntoView({block:'nearest',inline:'center'});}catch(e){}}});
if(o.scroll!==false){var el=t.el||t.sec,top=el.getBoundingClientRect().top+window.pageYOffset-offset();window.scrollTo({top:Math.max(0,top),behavior:(o.instant||reduce)?'auto':'smooth'});}
if(o.focus!==false){var f=t.el||t.sec.querySelector('h2');if(f){if(!f.hasAttribute('tabindex'))f.setAttribute('tabindex','-1');try{f.focus({preventScroll:true});}catch(e){f.focus();}}}
}
document.addEventListener('click',function(e){
if(e.defaultPrevented||e.button||e.metaKey||e.ctrlKey||e.shiftKey||e.altKey)return;
var a=e.target.closest('a[href^="#"]');if(!a)return;var h=a.getAttribute('href');if(h.length<2||!target(h))return;
e.preventDefault();if(location.hash!==h)history.pushState(null,'',h);go(h,{});
});
window.addEventListener('popstate',function(){go(location.hash,{});});
function setMode(a){all=a;document.body.classList.toggle('all',all);mAll.classList.toggle('on',all);mTabs.classList.toggle('on',!all);mAll.setAttribute('aria-pressed',all?'true':'false');mTabs.setAttribute('aria-pressed',all?'false':'true');try{localStorage.setItem('lp-mode',all?'all':'tabs');}catch(e){}}
mAll.addEventListener('click',function(){setMode(true);measure();go(location.hash,{instant:true,focus:false});});
mTabs.addEventListener('click',function(){setMode(false);measure();go(location.hash,{instant:true,focus:false});});
window.addEventListener('resize',measure);
measure();setMode(all);
// A face can arrive after a scroll was aimed (a section shown for the first time loads its heading face), and the
// layout above the target then moves a few pixels. Until the reader moves, the last navigation is re-aimed after each
// font batch, so the heading sits exactly under the bar.
var aimed=null,moved=false;
['wheel','touchstart','keydown','pointerdown'].forEach(function(ev){window.addEventListener(ev,function(){moved=true;},{passive:true});});
var go0=go;go=function(hash,o){go0(hash,o);aimed={hash:location.hash,at:performance.now(),instant:!!(o&&o.instant)};moved=false;};
function reaim(){measure();if(aimed&&!moved&&location.hash&&location.hash===aimed.hash&&performance.now()-aimed.at<4000)go(location.hash,{instant:aimed.instant,focus:false});}
window.addEventListener('load',reaim);
if(document.fonts){document.fonts.ready.then(function(){setTimeout(reaim,0);});document.fonts.addEventListener('loadingdone',function(){setTimeout(reaim,0);});}
if(location.hash)go(location.hash,{instant:true,focus:false});else go0('',{scroll:false,focus:false});
})();
</script>
</body>
</html>