Skip to content

Research · Network state

What the network has been doing

Own-chain research telemetry, read from committed dataset snapshots rather than live windows. Declared shapes are claims; a weight match proves the committed operand, never that inference ran; and every share below states its denominator.

Every figure reads the committed snapshots: the DS-003 network-state series frozen at tip 97,899 and the DS-004 entity clustering frozen at tip 97,900. Semi-live tier: a figure changes only when a new tagged snapshot is committed, so nothing here drifts silently, and nothing fetches live data. Rolling live windows stay on /mining. Figure numbers follow the research plan’s N-series; the census and clustering figures carry their Phase 14 numbers.

Kind of work

N1 · What was proven, and what was only declared

Above: blocks whose weight commitment was recomputed byte-exactly from a published checkpoint, per 1,000-block bin. Below, on its own axis: the share of the same bin declaring a reference-model shape, which consensus never checks.

  • Matched to published weights (proven)
  • Measured zero: hashed bin, no match
  • Model-shaped declared (a claim)
  • Frozen weight-scan bound

Overlay basis: 1,109 matched blocks, from the hashing runs this snapshot joined (DS-002-weight-scan-v1, DS-002b-gemma-v1, DS-002b-o-tp48-v1). OBS-005 reports 1,110 on the combined corpus, which also folds the later coverage-closure round; that round’s match is OBS-005’s last attested block, h68,332. Its bin therefore draws neither a bar nor a measured-zero tick here: this snapshot’s overlay holds no match in it, and that absence is not a measured zero. Neither figure corrects the other: they are different dataset unions, and the difference is stated rather than reconciled silently. A snapshot folding the closure round ships as a new dataset version, never as an edit to this one.

Denominator for every share here: canonical blocks per 1,000-block height bin; the final bin is partial at the tip. The matched panel carries counts rather than a share, since the bins are a fixed 1,000 blocks apart from that last one, so counts compare directly across them. Matched is the proven series: the block’s weight commitment was recomputed byte-exactly from a published checkpoint by the DS-002 scan family. It establishes which operand was committed and nothing after it, and only public static checkpoints can be checked at all. See OBS-005. The frozen scan bound h96,774 falls inside a bin rather than on a bin boundary: that bin is only partly hashed, so no whole-bin value is defined for it, and bins entirely above it carry no matched value at all because nothing in them was hashed. A fully hashed bin with no match keeps a baseline tick. Model-shaped is a declared claim: the certificate’s declared (n, k) matches a reference-checkpoint tensor shape, which is consistency with a shape and not evidence that those weights were used, nor that any model was run. The two are never stacked into one shape and never share an axis, so a claim cannot be read as a proof by area. The claim ladder in N7 below sets out what each rung can carry. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

N2 · The MoE window

Where mixture-of-experts certificates actually appear in chain history.

MoE proofs were legal from height 71,935 (PIP-2, the only consensus change with a proposal) to 91,630 (a softfork no document proposes). Certificates using them appear only in bins 84,00091,999: 1,929 of 97,900 blocks all time (2.0%), first appearing 12,065 blocks after legalization at this bin resolution, and none since the retraction.

Denominator: canonical blocks per 1,000-block bin; cell shading scales with each bin’s MoE share. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live. Full analysis: OBS-006.

Effort and its shape

N4 · Network effort and its shape

Per-bin work rate and difficulty, with the two declared-shape shares that evidence fleet transitions without naming anyone.

  • Work rate
  • Difficulty (end of bin)
  • m = 32,768 share
  • Power-of-two n share
  • Fleet-transition markers

Work rate per 1,000-block bin: the bin’s summed per-block work 2^256/(target+1), an exact integer in the dataset, divided by the bin’s wall-clock span; unit: matmul attempts per second, a difficulty-derived consensus measure, not a measure of AI computation performed. Block times are miner-set, so a non-positive span renders as a gap, never as zero. Difficulty is the bin’s last block. Shape shares are per-bin over canonical blocks: declared batch dimension exactly m = 32,768 (the constant-m stratum), and declared n a positive power of two. Shapes are miner claims; the transitions they evidence describe strata, not identified operators. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

Configuration against the rules

N3 · The legal boundary over height

Share of each bin declaring exactly rank 128 and k 2,048, the boundary-hugging configuration, with every height-gated consensus change inside this snapshot marked.

  • Share at rank 128, k 2,048
  • Consensus-change markers

Denominator: canonical blocks per 1,000-block bin; the final bin is partial at the tip. The pair (rank 128, k 2,048) is the cheapest legal configuration only after the rank-penalty softfork at height 96,251 (v1.3.0; no PIP documents it). Before that height the same pair was one common choice among many, not a legal minimum. The two earlier markers are the MoE hard fork at height 71,935 (PIP-2) and the dense-only softfork at height 91,630 (no PIP documents it either). The latest is the salted noise-seed hard fork at height 99,000 (v1.4.1, V3 certificates required, activated 2026-08-11, and again with no PIP): 4 height-gated consensus changes on mainnet in all. One of them is above this snapshot's last height 97,899, so it is named here rather than drawn at an invented position; the next frozen snapshot marks it. One further activated change is release-gated and carries no height, so no height axis can mark it; the consensus-change register carries all of them with their evidence. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

N3 · Declared k over height

Share of each bin by declared common dimension k; the six most common values named, the rest folded into Other.

  • k 1,024
  • k 2,048
  • k 4,096
  • k 8,192
  • k 16,384
  • k 51,200
  • Other k

Denominator: canonical blocks per 1,000-block bin; every canonical block in the series carries decoded parameters, so the shares stack to 100%, and the final bin is partial at the tip. Declared k is the common dimension of the certificate’s m×k by k×n multiply, a miner-chosen proof parameter, not throughput. The six named values are the most common over the whole corpus and cover 99.1% of all blocks; Other k folds the rest, including the genesis empty certificate’s k 0. The pair (rank 128, k 2,048) is the cheapest legal configuration only after the rank-penalty softfork at height 96,251; see the boundary panel. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

N3 · Declared rank, all time

Blocks by declared noise rank, aggregated over the whole corpus.

Denominator: all 97,900 canonical blocks to the snapshot tip. Declared noise rank is a miner-chosen proof parameter, not throughput. Ranks below 128 are invalid only since the rank-penalty softfork at height 96,251; the earlier population is legal history, not violations. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

14.3 · Boundary-hugging by pool

Per pool label, the share of its rank-128 certificates declaring exactly k = 2,048, the smallest legal k at rank 128, over the whole series.

  • At k = 2,048 (share of the pool’s rank-128 blocks)
  • Above the minimum

Denominator per row, the n= figure under each pool label: that pool’s rank-128 certificates over the whole series (48,071 blocks across all rows; unit: blocks), not its 97,900 total blocks. Pool names are coinbase labels, the same labels the pool directory uses; addresses are not entities and no label names a party. The smallest declared k at rank 128 anywhere in the series is 2,048; the pair (rank 128, k 2,048) is the cheapest legal configuration only after the rank-penalty softfork at height 96,251, and before it the same pair was one common choice among many. Sitting at, near, or far from the boundary are all legal configurations; this figure measures the distribution, nothing more. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

Which software the network runs

14.4 · Tile-signature software census

Per-bin share of decoded blocks by (tile geometry, rank, official-bytes) signature: which software builds the network runs, read as bytes.

  • 2x64 rank 128, official bytes
  • 8x16 rank 64
  • 4x16 rank 64
  • 16x16 rank 128
  • 8x16 rank 128
  • 8x16 rank 256
  • Other signatures

A signature is the certificate’s declared tile geometry (tileH x tileW), its noise rank, and officialBytes: whether the rows/cols tile patterns byte-match the official sm90 kernel fragment, the certclass byte test. A byte-signature census, descriptive only. Signatures fingerprint the software build that emitted the certificate; they identify software, never an operator and never the honesty of the work, and no signature is an identity claim. Matching bytes is an upper bound on unmodified official-stack use, and the byte test separates builds that geometry alone cannot: 2,315 blocks share a geometry-and-rank triple with an official-bytes signature while failing the byte test. Official-bytes signatures cover 25,820 of 97,899 decoded blocks (26.4%, whole series). Denominator: decoded non-EMPTY canonical blocks per 1,000-block bin (unit: blocks); the genesis EMPTY certificate decodes to no signature and is excluded, 1 block in the whole series. The series holds 38 distinct signatures; the top six by blocks are drawn and the remainder folds into Other. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

The mechanism and what it costs

N9 · How the protocol works, in one screen

The mechanism in four steps, source-verified against the published mining stack. Mining is the search for a tile whose keyed BLAKE3 commitment clears the difficulty target, BLAKE3(seed, tile) < 2^(256−b). One clause below is inferred and marked; everything else is verified.

  1. 01A forward pass is the work unit
    The official miner is a vLLM quantization plugin: it registers a pearl scheme and replaces quantized linear ops with a noisy GEMM kernel, so a genuine LLM forward pass doubles as the proof-of-work, and the kernel denoises so inference still gets the correct result. The mined call is a tiled INT8 matrix multiply: activations are int8 clamped to ±63 with per-token dynamic scales, and weights arrive pre-quantized. Shapes are opportunistic, not chosen: m is the live batch-token count, n and k come from the layer, and the same three values land in the certificate, so the chain records the true dimensions of whatever matrices were multiplied.

    Source: Keshi source review, pearl-src @ v1.3.0

  2. 02Where the noise overhead comes from
    Before the multiply, both operands are perturbed with deterministic rank-r noise (r = 128 on mainnet), seeded from the certificate’s own commitments. Two noising passes are genuine extra work, stated as fractions of the call’s base m·n·k INT8 MACs: the activation side costs 2r/n and the weight side 2r/m, and the weight side is two rank-r products because its seed depends on the activation commitment and cannot be cached. Denoising costs 2r/k and is fused into the GEMM epilogue on the resident accumulator, so there is no extra read or write of the m×n output. The transcript hash adds 1/(2r) of the op count on its own basis. The overhead lab below turns these terms into numbers.

    Source: Keshi source review, pearl-src @ v1.3.0

  3. 03Acceptance is dimensional
    Consensus checks ranges, never contents. The verifier enforces: rank a power of two in [32, 1024] and divisible by 16; k divisible by 64 with 1,024 ≤ k ≤ 65,536 and 16r ≤ k ≤ 4r²; tile h·w in [32, 256] with h and w even; m and n at most 2^24. Nothing constrains matrix contents or provenance: the accepting predicate is purely dimensional plus the difficulty comparison, so any matrices that satisfy it are accepted. The reference CPU miner draws fresh random matrices every iteration; the redraw is that path’s documented nonce mechanism.

    Source: Keshi source review, pearl-src @ v1.3.0

  4. 04The configuration surface
    Engagement floor
    The official stack mines a GEMM call only above min_m=1024, min_n=256, min_k=1024. These are miner-side YAML defaults, not consensus constants. Below the gate the call routes to pearl_gemm_vanilla, a plain GEMM with no noise and no hashing, so a decode step with fewer than 1,024 concurrent sequences never mines.
    Skip flags
    The kernel exposes skip_reduction and skip_denoising, a path that would produce hashrate without restoring a usable inference result. In the published source those flags appear only in tests, and the production path passes both false (verified). The certificate carries no record of them (inferred: the documented 164-byte public-data layout holds dimensions, rank, tile patterns and commitments, no kernel flags).
    Rank and tile patterns
    Noise rank is a miner-chosen proof parameter, not throughput. The shipped kernel compiles only ranks 64 and 128, and MINER_* environment variables can override rank, patterns and tiles. Since height 96,251 consensus rejects rank below 128 and multiplies the difficulty bound by 128/rank.
    Shape choice
    The official stack takes its shapes from live traffic. Custom software may declare any shape the predicate accepts; the declaration is a claim (the ladder below grades it).

    Source: Keshi source review, pearl-src @ v1.3.0

neutral mechanismEach row of the configuration surface is something the published software permits, reported as measurement. Whether any given operator uses a configuration is a separate question this panel does not answer. What a certificate can and cannot prove is the claim ladder (N7, below).

N8 · The overhead lab

Noise tax against the batch dimension m at n = 57,344, k = 8,192, r = 128 (set in the calculator), over the network's recorded m masses.

  • MAC-count overhead (verified arithmetic)
  • Time-weighted overhead (inferred)
  • Blocks declaring exactly this m (DS-003)
  • min_m = 1,024 floor (miner default, not consensus)

Denominator and unit, top panel: extra work per mined GEMM call as a fraction of that call’s base m·n·k INT8 MACs at the shape shown (MAC-count sum 2r/n + 2r/m + 2r/k: verified arithmetic; the time-weighted curve assumes fp16 denoise at half the INT8 rate: inferred). Denoising is fused into the GEMM epilogue, so there is no extra read or write of the m×n output. Not drawn, all on other bases: the transcript hash at 1/(2r) of op count (verified), an unquantified transcript-stall term (inferred) and fixed per-call traffic of roughly 0.5 GB hash sweep plus 1 GB noising read and write (inferred). Bottom panel: blocks declaring exactly that m as a share of all 97,900 canonical blocks (lower bounds from the per-bin top-mass projection; m = 0, the genesis empty certificate, excluded). The floor is the official miner’s YAML default, not a consensus constant. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

The noise-tax calculator

The same formula the source pass verified, recomputed for any shape. All percentages are fractions of one mined call’s base m·n·k INT8 MACs.

Verified anchors
Noising A · 2r/nactivation-side (A); one rank-r product
0.45%
Noising B · 2r/mweight-side (B), activation-seeded; two uncacheable rank-r products
1.56%
Fused denoise · 2r/kin the GEMM epilogue; no m×n round-trip
3.13%
MAC-count totalverified arithmetic5.1%
Time-weighted totalinferred8.3%
Transcript hash · 1/(2r)of op count, its own basis; in neither total
0.39%

At the dominant 70B gate_up shape (n = 57,344, k = 8,192, r = 128) this formula gives 28.6% at m = 1,024, 5.1% at m = 16,384, 4.4% at m = 32,768 (MAC count, verified arithmetic), matching the source pass exactly.

Unit of analysis: one mined GEMM call; nothing here is a fleet or wall-clock measurement. Not modelled, all inferred: an unquantified transcript-stall term (the tensor pipeline drains every r of K depth, mid-single-digit percent) and fixed per-call traffic independent of m, roughly 0.5 GB tensor-hash sweep plus 1 GB noising read and write; at the m = 1,024 floor those fixed passes are of the same order as the base GEMM itself.

Merged vs corner: the equilibrium condition

A third-party equilibrium model prices compute allocated across pure mining, pure inference, and duplex work that produces both. In our own framing of that model (not verified against the paper text), a duplex operation yields 1/α units of inference and 1/γ units of proof-of-work security for α, γ ≥ 1, and duplex work beats the corner split exactly when

(α − 1)(γ − 1) < 1equivalently 1/α + 1/γ > 1

(α − 1)(γ − 1) = 0.0261/α + 1/γ = 1.618

In the model, merged (duplex) work is strictly cheaper than replicating its output with the corner split of pure mining plus pure inference.

γ asks how much proof-of-work security a duplex operation loses against a pure miner’s. No measurement of it exists anywhere, which is why the model’s regimes stay unresolved for this network. The α prefill uses the MAC-count basis (verified arithmetic); a wall-clock α would differ and is unresolved (inferred bounds only).

Community claims, with source verdicts

Benchmark figures that circulate in community threads, each shown as the unverified claim it is, with the verdict the kernel source supports.

  • unverified claim~15% overhead at batch 64
    source verdictnot what it measures

    m = 64 is below the official stack’s 1,024-row engagement floor, so the call routes to pearl_gemm_vanilla: a plain GEMM in which no noise, hash or denoise work runs. Any real slowdown at batch 64 is the always-on int7 mining quantization or plugin machinery, never the noise mechanism.

    Source: Keshi source-verification pass, pearl-src @ v1.3.0

  • unverified claim40%+ decode throughput loss
    source verdictplausible only at the floor

    Plausible only at the m ≈ 1,024 floor, where the formula gives 28.6% of base MACs (verified arithmetic) and 31.7% time-weighted (inferred), plus the fixed per-call passes (inferred). False for typical decode, which sits below the engagement floor and does not mine at all.

    Source: Keshi source-verification pass, pearl-src @ v1.3.0

Claim denominators are whatever each claimant measured; they are stated here only through the verdicts, whose basis is one mined GEMM call’s base m·n·k INT8 MACs. Neither claim names its rig or method, and this page names no operator or pool.

Concentration and attribution

N5 · Concentration over height

Per-bin Nakamoto coefficient on both accounting bases, with the unattributed remainder always in view.

  • Nakamoto, all blocks
  • Nakamoto, attributed only
  • Unattributed share

Unit: labelled pools per 1,000-block bin. The all-blocks basis counts the fewest labelled pools whose combined share exceeds half of every block in the bin; the attributed basis does the same over attributed blocks only. Bins where a basis is undefined (for example when labelled pools cannot reach a majority of all blocks) render as gaps, never as zero. The unattributed share is never hidden and never redistributed. Pools and addresses are not entities: see the DS-004 panel below. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

N6 · Who is mining, structurally

Distinct decoded payout addresses per bin, and the largest share of a bin's blocks paid to a single address.

  • Distinct payout addresses
  • Top-address share of bin blocks

Units: distinct decoded coinbase payout addresses per 1,000-block bin, and the most blocks paid to a single address as a share of the bin’s canonical blocks. Exactly one block in the whole series, in the first bin, has no decoded payout address. Addresses are not entities: one operator can split rewards across many addresses and one address can collect for many machines, so this figure reports structure, never identity; the DS-004 panel below carries the entity basis. Per-operator matched-block marking is deferred until the OBS-005 operator wave lands. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

N10 · Attribution census: the unknown-hashrate answer

Community threads quote pool-site “unknown hashrate” percentages with no denominator. This is the checkable version: every share below states what it divides by.

Blocks basis (exact)

Labelled pools
31.2%
30,504 of 97,900 canonical blocks
Unattributed
68.8%
67,396 of 97,900 canonical blocks

Difficulty-weighted work basis (within-bin apportionment)

Labelled pools
74.6%
of 2.14e+26 matmul attempts, the series' summed 2^256/(target+1)
Unattributed
25.4%
the remainder of the same work denominator
Nakamoto coefficient, attributed-only basis
2
labelled pools whose blocks exceed half of the 30,504 attributed blocks, whole series
Nakamoto coefficient, all-blocks basis
undefined
undefined because labelled pools together never reach half of the 97,900 canonical blocks; that is a fact about label coverage, not safety

Neither Nakamoto figure is quotable without its basis. Addresses are not entities: pool labels attach to coinbase payout addresses, one operator can span several addresses and pools, and no label names a party. The co-spend measurement of that gap is the entity panel below and OBS-009. The work basis apportions each bin’s exact integer work sum to pools by block count inside the bin (an inferred step; per-block work stays in the dataset); block counts and totals are exact. The bases diverge because the unattributed mass sits mostly in early low-difficulty bins. Rolling 24h/7d/30d label windows stay live on /mining. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

N10 · Attribution history by pool

Per-bin share of all canonical blocks by labelled pool, with the unattributed remainder always in view.

  • PearlHash
  • Pearl Fortune
  • Kryptex
  • LuckyPool
  • Hero Miners
  • Unattributed

Denominator: all canonical blocks per 1,000-block bin, so the stack always sums to 100% and the unattributed remainder is never hidden or redistributed. Within a bin, block shares equal bin-uniform work shares by construction; the whole-series work basis in the census above diverges because later bins carry vastly more work per block. Addresses are not entities: pool labels attach to coinbase payout addresses, one operator can span several addresses and pools, and no label names a party. See the entity panel below. Data tier: semi-live, frozen at DS-003 tip 97,899; read from the committed snapshot, never fetched live.

14.1 · Who is mining: addresses vs entities

Co-spend clustering groups 9,561 miner addresses into 9,303 entities; every concentration figure moves with the basis.

Address basis

Miner addresses
9,561
Nakamoto coefficient
49
Effective units
36.90
Top-1 share
11.1%

Entity basis

Entities
9,303
Nakamoto coefficient
12
Effective units
28.28
Top-1 share
11.1%
Largest entity
10,861 blocks from 1 address
Multi-pool entities
0
Largest unattributed cluster
107 addresses, 8,931 blocks

Largest clusters by blocks

Representative addressBlocksAddressesPools
prl1p50ltku2…cchnnm10,8611PearlHash
prl1p05tqqdf…0gyl7t8,931107unattributed
prl1pl7ch5q7…2f3xjw8,2091Pearl Fortune
prl1puv0gqv4…mqaqsh5,5761Kryptex
prl1p2w3ruv4…tvxq7h3,4701unattributed

Clusters are lower bounds on linkage, never identities: co-spend joins addresses whose coinbase outputs were spent together, so one operator can still appear as several clusters, and no cluster names a party. The entity collapse is a historical genesis-era fact, not a current-window threat: the largest unattributed cluster went dark at height 30,768. Denominator: 97,900 blocks with a decoded coinbase payout address. Data tier: semi-live, frozen at DS-004 tip 97,900; read from the committed snapshot, never fetched live. Full analysis: OBS-009.

What can be verified

N7 · What a certificate proves

The claim ladder: each rung is strictly weaker evidence than the one below implies. Reading a figure above this rung boundary is over-reading it.

  1. 01Declared shapea claim

    The certificate carries the matrix dimensions the miner says were multiplied (m, n, k) plus rank and tile parameters. Consensus checks their ranges, never their truth: any matrices that satisfy the predicate are accepted.

  2. 02Committed operandprovable, public checkpoints only

    The certificate commits byte-exactly to the weight-side matrix with a keyed BLAKE3 root. Recomputing that root from a published checkpoint proves which operand was committed, and only public, static checkpoints can be checked at all: private, fine-tuned or evolving weights are indistinguishable from noise.

  3. 03Declared matmul, inference, customersnever provable on chain

    The ZK proof opens at most 256 output entries of the declared result. It never proves the full declared multiplication ran, that inference occurred, or that anyone was served.

Declared dimensions are what the miner claims was multiplied; the ZK proof covers at most tileSize ≤ 256 output entries of the result, never the full declared matmul, and never a measure of AI work performed.