Home Protocol Architecture Tokens Roadmap FAQ Whitepaper Economics GitHub ↗
Testnet-10 H-001 confirmed · Full rollout gated

The security the world
never controlled.

Prometheus is building toward decentralized, AI-assisted threat intelligence on Kaspa. The repository contains tested development foundations and one non-promotable Testnet-10 canary; no production protocol network or PROM emission is active.

0%
Pre-mine · Founder allocation · Investor tranche
<60s
Target lifecycle; not production evidence
100%
Source available · MIT License · operation not decentralized yet

01 / Protocol

Target: on-chain in under 60 seconds.

The target path from anomaly to validated Kaspa rule after proof, observable, consensus, and rollout gates pass. Current verified ThreatHint v1 is deliberately non-actionable.

t=0s
T = 0 s
Light Client
Target: Phi-3-mini detects locally; artifact hash and privacy-filtered observable commitment are bound by an approved, precisely scoped proof.
ONNX Runtime
Groth16 ZK-proof
libp2p
t=2s
T = 2 s
Guardian Node
Target: 8B-first analysis with 70B escalation. Current evidence has no independently evaluated real-model run; YARA output is non-actionable or synthetic.
LLaMA 3 70B / 8B
vLLM · YARA
Min confidence 0.85
t=15s
T = 15 s
Validator Network
Tested state machines: Commit-Reveal, 10% bond, and 67% quorum. No operated validator network or decentralized membership is proven.
Silverscript
Commit-Reveal
Bond system
t=35s
T = 35 s
Kaspa Layer 1
Target: canonical rule state and CID on Kaspa, content on IPFS, with explicit rule deactivation. Asset orchestration, availability, replication, and censorship resistance remain open.
DAGKnight
KRC-20 (supply=1)
IPFS CIDv1
t=36s
T = 36 s
All Clients
Target: P2P distribution or Kaspa polling and verified local loading. GH-190 verifies bounded caller-supplied exact bytes against Raw-CIDv1. Merged and exact-main-verified GH-197/PR #198 checks one separately owner-pin-hashed Testnet-10 manifest against bounded RuleStorage UTXO observations before local state decoding. GH-203/PR #204 adds a bounded development-only query to one connected Testnet-10 node. GH-205 composes that path with a credential-free loopback-only local IPFS gateway, exact CID/content binding, and one atomic complete-snapshot scanner replacement. GH-207 adds owner-local restart-persistent rollback and same-order equivocation rejection with exact replay recovery. GH-209 adds bounded opt-in development orchestration with retry backoff, per-attempt timeout, shutdown cancellation, and single-flight execution. GH-211 authenticates one strict canonical complete-snapshot envelope with BIP340 against a separately owner-pinned key, external nonzero minimum sequence, and separately trusted per-fetch clock. Merged and exact-main-verified GH-213/PR #214 at bbe7efb adds an operator-invoked Development/Testnet-10 preflight/run CLI with private strict local files, offline non-mutating preflight, loopback-IP-literal RPC/IPFS, redacted status, and signal cancellation; CI 31950806131, Security 31950806118, and Pages 31950805653 pass. It adds no signer, key-authority/rotation proof, persistent sequence authority, autonomous provider, wallet or chain write and is not an independently authenticated canonical L1/IPFS source, availability or replication proof, chain-truth or finality proof, deployment, or public rule-distribution network.
Merged and exact-main-verified GH-216/PR #217 at 13c1812 adds test-only real-binary loopback E2E evidence for offline/connected preflight, private checkpoint commit, SIGTERM/SIGINT drain, restart exact replay, rollback/equivocation rejection, and malformed, timeout, or disconnected peers; CI 31978132036, Security 31978132044, and Pages 31978131647 pass. This is local Development evidence only, not public Testnet operation, independent RPC/IPFS truth or availability, deployment, Mainnet, or production readiness.
rusty-kaspa
libp2p broadcast
Local YARA engine

02 / Architecture

Three target layers.
Trust gates visible.

Target properties remain distinct from implemented fixtures, Testnet evidence, and production deployment.

1 Kaspa Layer 1
Canonical state target
  • DAGKnight consensus · 100 BPS
  • Silverscript smart contracts
  • Target PROM-RULES asset orchestration; current gate covers state/CID transitions
  • Native Groth16 ZK-verification
  • Sub-second finality
  • ValidatorStaking · RuleStorage
2 Optional services
Non-canonical views
  • Analytics and dashboards
  • Optional reward views
  • Planned secondary-market interfaces
  • Cannot override canonical L1 reputation
  • No Kasplex dependency for reputation
  • No service is production-deployed
0 Off-Chain · Device
Action layer
  • Target: Phi-3-mini local inference
  • Target: LLaMA 3 Guardian analysis
  • Target: Fed-DART federated learning
  • Local files and paths stay local; bounded metadata is explicit
  • P2P coordination via libp2p
  • Deterministic bounded automation; rollout gates remain explicit

GH-258/GH-261 is planned, not implemented: future endpoint detection includes unauthorized compute conscription of endpoints, accelerators, servers or data-center capacity into a distributed mesh. It would classify observable process/resource ownership, unexpected CPU/GPU workload, scheduler/orchestrator drift, workload-identity and outbound fan-out signals, not claim reliable AI/AGI attribution. The staged target is observe-only, warn-only, operator-confirmed reversible containment, then separately approved limited automation. No real-time endpoint sensor or response engine is implemented; quarantine, process termination, firewall mutation, credential rotation, remote commands, deletion, and host isolation are disabled and unauthorized.

GH-264 observe-only parser candidate: Rust and Python share one 512-byte-capped canonical statement with closed behavior domains/signals, bounded counts/windows, an opaque nonce, minute-granularity time and a separately trusted network. It reads no endpoint data, has no free-text or host-identifying fields, and proves no event truth, maliciousness, privacy, AI/actor attribution or authorization. No sensor, correlation, warning, transport, response authority or production behavior is added.


03 / Node types

Four target roles.
Participation remains gated.

01 · Light Client
Light Client
Target: local Phi-3 inference with explicit, bounded reporting. Current v1 sends claim metadata but no concrete IOC and makes no anonymity guarantee.
4 GB RAM · No GPU required
Windows · macOS · Linux · ARM
02 · Guardian
Guardian Node
Target: 8B-first/70B-escalation analysis and rule proposals. No independently evaluated real-model run, actionable authority, or active PROM rewards exist.
8B: NVIDIA GPU, 24 GB VRAM
70B: 4× A100 / H100 80 GB
03 · Validator
Validator Node
Target: stake KAS, never PROM, and vote through Commit-Reveal. State machines are tested; no operated validator network is proven.
Minimum 10,000 KAS stake
Standard server · No GPU needed
04 · Honeypot
Honeypot Node
Planned isolated decoy role for verified discoveries. Not implemented; no capture, analysis, or PROM reward is active.
Target: isolated internet-exposed server
Reward path not implemented

04 / Economics

Two tokens.
No shortcuts.

Validators stake KAS, never PROM. Planned primary PROM issuance is contribution-based; a later KAS/PROM pool would enable secondary trading.

KAS Token
KAS
Kaspa native token · Validator staking
Target contract behavior uses KAS collateral. Tested state machines encode penalties, but no operated validator network currently stakes or slashes funds.
Tested minimum10,000 KAS · adjustment state machine
Tested penalties5% simple · 10% double-vote · 20% collusion
Tested cooldown7 days on exit
SourceKaspa network · 0% pre-mine · fair launch
Liquidity$1B+ market cap · no bootstrap needed
PROM Token
PROM
Planned reward & governance token
Minting, emission, liquidity, and trading are not implemented, deployed, or active. Guardian reputation is separate L1 state.
Year 120,000,000 PROM · −10% per year
Validators40% · for validated rules
Guardians30% · for accepted proposals
Reporters20% · Light Clients + Honeypots
Dev Pool5% · planned DAO-governed allocation
Community5% · planned protocol allocation

05 / Numbers
160+
Tests passing
6
Silverscript contracts
<60s
Target; current fixture is same-host and stubbed
0%
Pre-mine

06 / Roadmap

Built in public.
Audited in public.

Sprints, findings, evidence, and remaining gates are tracked in the public repository.

Mar 2026
Sprint 0 — Setup & Testnet
Kaspa Testnet-10 node · repository structure · CI/CD pipeline
Accepted
Mar 2026
Sprint 1 — Silverscript Contracts
6 contracts · 54 tests · ValidatorStaking · GuardianReputation · RuleStorage
Accepted
Mar 2026
Sprint 2–3 — Rust Client & AI
Kaspa RPC · YARA scanner · Phi-3 wrapper · ZK-proof stub · Fed-DART
Accepted
Mar 2026
Sprint 4–5 — Guardian & Voting
vLLM Docker · YARA generator · Commit-Reveal · slashing engine
Accepted
Mar 2026
Sprint 6–7 — E2E & Documentation
Development-stub lifecycle fixture <60s · security tests · audit dashboard · whitepaper; not production evidence
Accepted foundation
Apr 2026 onward
Community workstream
Gitcoin Grants · public repository · external contributors; separate from accepted Sprint 8 Public Site delivery
In progress
Aug 2026
H-001 testnet-10 canary — 100% confirmed
external signature · full transaction verification · one-shot broadcast · confirmation · canonical operator receipt · independent public evidence · non-promotable canary only
Confirmed
Aug 2026
GH-167 bounded ThreatHint-v2 transport
exact Rust/Python frame · independent libp2p v2 channel · owner-only IPC · trusted session/time resolution · exact-main CI/Security/Pages verified · repository substrate only
Verified
Aug 2026
GH-170 bounded YARA-X validation
exact-pinned compile-only engine · one bounded rule · imports/includes and warnings rejected · no scan · exact-main CI/Security/Pages verified
Verified
Aug 2026
GH-173 deterministic semantic draft
approved v2 observables · memory-only candidate · nonce-bound binding/verdict persistence · exact-main CI/Security/Pages verified · no model, scan, submission, or production authority
Verified
Aug 2026
GH-177 synthetic YARA quality gate
20 deterministic in-memory cases · exact corpus/policy/evaluator binding · authority none · PR #178 merged at exact main 396d347 · CI, Security, and Pages pass
Verified
Aug 2026
GH-180 offline v2 pipeline integration gate
canonical synthetic transport to durable non-actionable result · replay, concurrency, lease, and rollback evidence · 1303 Guardian tests passed and 4 intentional live-model tests skipped · PR #181 merged at exact main a28ad00 · CI, Security, and Pages pass · not production-deployed
Verified
Aug 2026
GH-226 Light Client v1 submission
Development-only · one static literal-loopback Guardian QUIC peer · exact canonical bytes · owner-only files · real same-host binary evidence · PR #227 / exact main 6c39af5 · CI, Security Audit and Pages pass · no public multi-host or production operation
Verified
Aug 2026
GH-229 controlled distinct-host evidence
Merged capability PR #230 · exact main fba8bb4 · one operator-attested Development/Testnet-10 direct-QUIC run from source 27e8b02 on two distinct controlled hosts · rejected/rejected · zero retries · not persisted · temporary UDP rule removed · redacted evidence · no independent separation proof, public network or production claim
Demonstrated
Aug 2026
GH-234 ThreatHint-v2 submission
PR #235 · code b450740 · exact main f146fb2 · CI 33272578070 · Security 33272577951 · Pages 33272577407 · Development/Testnet-10 only · owner-only canonical shared v2 payload · separately trusted network parse before identity/network · exactly one Guardian v2 request · real same-host binary/QUIC tests · no proof or approval authority, public multi-host evidence, deployment or production claim
Merged
Aug 2026
GH-242 membership-bound ballots
Merged and exact-main verified via PR #243 at 5cb132c670d1e7771ccaf6dab2ddf5b1a6fd905a · CI 33433012614 · Security 33433012605 · Pages 33433011653 · owner-loads one canonical GH-147 membership source · separately trusted network and expected epoch · internally derived snapshot and public BIP340 signer map · no caller-built context registration · unchanged ballot wire, replay and ensemble math · no external membership authority, key rotation, Sybil, L1 attestation or production claim
Verified
Sep 2026
GH-246 membership continuity
PR #247 · exact main f12e821bb492caae3b94e5b3c882488eb7f2982d · CI 33452085421 · Security 33452085419 · Pages 33452084065 · canonical BIP340 signed transitions · owner-only durable current source, epoch, clock, replay and equivocation state · BallotIngress consumes current source under the same lock · 1348 Guardian tests pass, 4 intentional live-model skips · no external authority, key rotation, Sybil, L1, deployment or production claim
Verified
Sep 2026
GH-253 authority rotation
PR #254 · exact main 5920cb4bb737376977f762beb0d5e3108519c7a0 · CI 34031999904 · Security 34031999907 · Pages 34031999575 · owner-local dual BIP340 current-key authorization and proposed-key possession · gapless durable authority epochs · current membership/time/nonce binding · transactional schema-v1 migration · later transitions use only the current durable key · no signer/private-key path, real-world key ownership, external/decentralized authority, Sybil, L1, deployment or production trust
Verified
Readiness-gated
Complete roadmap vision — 50–55%
core rollout 84–88% · bounded v2 repository transport substrate · production proof approval · privacy-reviewed semantic analysis · operated multi-host P2P · clients · production network · vProgs
In progress
The fire belongs

to humanity,
not to corporations.

The contract design has no repository-controlled emergency-stop entrypoint. Current policy and membership inputs remain owner-controlled, and no public multi-host protocol network is operating. Availability and decentralized control are target properties, not current guarantees.

Join on GitHub Read the Whitepaper
MIT License  ·  0% Pre-mine specified  ·  Public repository  ·  Operation not decentralized yet