The fire belongs to humanity,
not to corporations.
Prometheus is an open protocol project building toward decentralized, AI-assisted threat intelligence on Kaspa. The repository proves development foundations and one non-promotable Testnet-10 canary, not a production or fully decentralized network. Current evidence relies on owner-controlled policies, membership files, local trust anchors, and same-host tests.
The target combines on-device Phi-3/ONNX inference, 8B-first/70B-escalation Guardian analysis, and Kaspa L1 canonical state/CID anchoring. Real Phi-3 inference, independently evaluated real Guardian models, public multi-host operation, decentralized membership/key rotation, Sybil resistance, on-chain attestation, and IPFS availability remain unproven.
Key properties: 0% pre-mine · No repository-controlled emergency-stop entrypoint · Automated governance target · Data-minimal on-chain state. Applicable privacy obligations depend on deployed data flows and jurisdiction; this whitepaper is not a legal determination.
| Parameter | Value |
|---|---|
| Blockchain | Kaspa BlockDAG / DAGKnight path, high-throughput PoW settlement |
| Smart Contracts | Silverscript — H-001 plus ValidatorStaking, GuardianReputation, RuleStorage, CommunityDonations, DevIncentivePool, and GovernanceAutoTuning current-Silverc gates verified |
| Genesis Operator | Keyless Toccata-v1 assembly with exact contextual storage mass, final 66-byte Schnorr-script mass modeling, signed-request schema-v2 relay/operator fee floors, exact live funding-UTXO validation before preparation and broadcast, external BIP340 digest signing, canonical public signature import with path-collision guards, full verification before output, crash-consistent acknowledged broadcast, transaction-ID retry reconciliation, source-bound covenant UTXO observation, and per-request wRPC deadlines; 38 unit/security tests; testnet-10/mainnet supported by pinned v2.0.1 while resolver mode is testnet-10-only |
| Deployment Profiles | full binds all seven release fixtures and the public metrics-oracle key. testnet-10-validator-staking-h001 binds only ValidatorStakingH001 to the TLS-only official resolver, omits the oracle key, and cannot promote full or metrics readiness. |
| Guardian AI target | 8B-first/70B escalation; runtime scaffold exists, no independently evaluated real-model run |
| Client AI target | Phi-3-mini ONNX; current code is a bounded fail-closed safe-default stub with no ONNX session, loaded-model claim or quarantine authority |
| Federated Learning | Fed-DART (Fraunhofer Institute) |
| Staking Token | KAS (Kaspa native, 0% pre-mine) |
| Governance Token target | PROM tokenomics specify 0% pre-mine; minting, emission, liquidity, and trading are inactive |
| Total Emission (5 years) | 80,000,000 PROM |
| Mainnet Launch | The non-promotable H-001 Testnet-10 canary completed external signing, full verification, one-shot broadcast, confirmation, operator receipt, and independent evidence on 2026-08-12. Canary success cannot authorize Mainnet; the remaining six state deployments, real oracle/sponsor signatures plus successor evidence, production proof approval, multi-host operation, and exact-commit release hardening remain required. |
| License | MIT |
Current implementation boundary: The first miner-facing feature is an experimental, opt-in prometheus-client miner-companion sidecar. It observes only a credential-free local Testnet-10 wRPC endpoint. Kaspa ASIC/pool mining normally uses Stratum, a separate protocol; this code does not modify firmware, reuse a Stratum session, scan the host, submit threat reports, run validators or honeypots, or award PROM. Beta/mainnet remain blocked by the real Phi-3, ZK, rule-distribution, and transport work.
Merged GH-117 v2 retention governance: A read-only owner policy declares the exact network, approver, recipient scope, canonical bundle payload form, durable observable kinds, and bounded local retention. The loader itself creates no database or outbox and grants no privacy, transport, disclosure, or rollout authority; governed enqueue uses its exact snapshot atomically.
Merged GH-117 v2 enforceable governance: One owner policy binds network, approver, recipient scope, authority epoch/window, same-Guardian local-analysis semantics, denied external disclosure, and explicit per-kind risk decisions. First valid governed acceptance atomically pins the exact promotion, governance, and retention policy digests with replay state and approval consumption. This grants no transport, chain action, or production artifact approval.
Merged GH-117 v2 recoverable outbox and non-actionable worker: Governed promotion inserts the full canonical Observable Bundle in the same SQLite transaction as authority state, replay high-water, and approval consumption. Full-queue or enqueue failure rolls everything back. Owner-local claim recovers after restart or lease expiry, and atomic completion stores one canonical non-actionable result before deleting work. The bounded worker uses only a deterministic test analyzer; no real semantic/actionable analysis, transport, disclosure, wallet, chain, deployment, or external effect is added.
Merged and exact-main-verified GH-170 - bounded YARA-X validation: Generated candidate source is compiled in memory with exact-pinned yara-x==1.4.0. Exactly one bounded ASCII rule is allowed; includes, imports, multiple rules, compiler errors, and warnings fail closed. No scan occurs, and no semantic, submission, publication, or production authority is added. PR #171 published exact main 8d8e29c; CI 31650123073, Security 31650123055, and Pages 31650122593 pass.
Merged and exact-main-verified GH-173 - deterministic non-actionable semantic draft: One optional governed-worker analyzer derives a bounded memory-only YARA draft from already approved local API-import and byte-pattern observables, compile-checks it through GH-170, and atomically stores only exact bindings, per-kind counts, a nonce-bound candidate-binding SHA-256, and compile status. Existing v1 results remain readable. PR #174 published exact main 1107b11; CI 31654308969, Security 31654308964, and Pages 31654308875 pass. No source, model output, confidence, should_submit, scan, disclosure, publication, wallet, chain, reward, deployment, semantic-quality claim, or production authority is added.
GH-177 merged and exact-main verified - isolated synthetic YARA semantic-quality evidence (not production-deployed): One standalone offline evaluator scans only 20 bounded deterministic synthetic in-memory buffers with a fixed GH-173-shaped rule under exact-pinned yara-x==1.4.0. Its canonical authority-none report binds exact corpus, policy, evaluator bytes, engine version, rule digest, confusion counts, and precision/recall/specificity. PR #178 merged as exact main 396d347; CI, Security Audit, and Pages pass on that SHA. This is synthetic regression evidence only, not real-world detection quality, actionable analysis, calibration, certification, or production authority.
GH-180 merged and exact-main verified - deterministic offline ThreatHint-v2 pipeline integration gate (not production-deployed): Eight POSIX-only cases compose canonical synthetic transport bytes through real Python ingress, governed promotion, schema-v5 atomic acceptance/outbox, bounded worker, and the durable GH-173 non-actionable semantic-draft result. They prove exact bindings plus fail-closed malformed/oversized input, replay/restart, duplicate concurrency, lease recovery, redacted analyzer failure, and transactional rollback. Local evidence includes 171 adjacent tests; 1303 Guardian tests passed and 4 intentional live-model tests skipped. PR #181 merged as exact main a28ad00; CI 31662874366, Security Audit 31662874399, and Pages 31662873670 pass. No product runtime, GH-177 wiring, real sample, public network, model, scan, actionable authority, deployment, or production certification is added.
The security industry is structurally compromised.
Classical antivirus software works by comparing files against a database of known malware signatures. This approach has a fundamental design flaw: it only detects what is already known. New, unknown attacks — zero-day exploits — pass through undetected.
State-sponsored trojans like Pegasus (NSO Group), Predator (Intellexa), and FinFisher were specifically engineered to bypass these detection mechanisms. They use zero-click exploits — the user need not click anything or download anything. A single incoming message is sufficient for complete device compromise.
The commercial security industry suffers from a fundamental conflict of interest: the same firms that sell protection also sell attack tools to governments. Firms like NSO Group, Hacking Team, and Intellexa profit from enabling espionage — not from preventing it.
- Zero-day market: A legal but opaque market for security vulnerabilities. Governments pay millions for unknown exploits.
- Backdoor laws: The US Cloud Act and similar legislation in other countries compel technology companies to cooperate with authorities.
- Conflict of interest: An antivirus company that simultaneously serves government clients has a financial incentive not to detect government malware.
Trustworthy security research does not come from the large corporations — it comes from independent actors: Amnesty International Security Lab (MVT toolkit for Pegasus detection), The Citizen Lab (University of Toronto — the leading address for uncovering state cyber-espionage), ClamAV (fully transparent, community-maintained open source scanner), and Wazuh (open source threat detection platform).
Prometheus builds on this tradition — and scales it to global network effects through blockchain technology.
Target swarm intelligence. Tamper-evident state. AI analysis.
Prometheus solves the three core failures of the current security industry simultaneously:
| Failure | Prometheus Solution |
|---|---|
| Centralization | Target: no foundation or central protocol server. Contract design has no repository-controlled emergency-stop entrypoint; availability still depends on Kaspa, nodes, clients, and network access. |
| Latency | Target: threat to on-chain rule in under 60 seconds after proof, observable, consensus, and rollout gates pass. |
| Misaligned incentives | Specification target: 0% pre-mine and primary issuance for verified contributions. A later KAS/PROM pool would allow secondary trading; no minting, emission, liquidity or trading is active. |
The current verified ThreatHint v1 path stops before Guardian analysis: it transports a caller-supplied hash commitment and bounded metadata but no concrete IOC, then returns zero confidence, no rule, and no submission. It does not derive the hash from an artifact or prove report truth, artifact derivation, or reporter anonymity. GH-82 specifies a separate artifact-hash and observable-commitment v2 boundary. Merged and exact-main-verified GH-86 adds isolated Rust and Python canonical bundle validators against one shared byte-exact corpus. Merged and exact-main-verified GH-90 adds one local Rust producer that computes a single file_sha256 observable from exact caller-supplied bytes and typed scope; Python independently validates the shared producer vectors. This proves only deterministic derivation at that function boundary, not that the bytes came from a real file, are malicious or privacy-approved, or are bound by a proof. Merged and exact-main-verified GH-94 additionally derives one bounded byte_pattern from exact caller-supplied bytes, checked offset, boolean wildcard mask, and typed scope. It accepts no pattern string, requires at least eight fixed bytes, and always emits local-only review_required_v1; Python independently validates the shared vectors. It does not authorize disclosure or transport or prove external provenance, maliciousness, privacy approval, or proof binding. Merged and exact-main-verified GH-114 additionally provides isolated local canonical v2 statement parsing and digest parity for distinct artifact-hash and observable-commitment fields. None of these slices is connected to v1 transport, proof verification, Guardian analysis, or rule publication. Reviewed privacy gates, the remaining kind-specific extractors, a reviewed v2 relation and approved proof artifacts, owner-only pairing, transport, and actionable analysis remain required.
Merged and exact-main-verified GH-103 adds one bounded local Linux ELF api_import producer. It accepts exact artifact bytes plus a checked index only, derives linux/elf scope internally, caps parsing at 16 MiB and 4096 dynamic symbols, validates the closed ASCII grammar, and sorts/deduplicates before selection. Every output is local-only review_required_v1; Python independently parses the shared exact-byte ELF vectors. No path or import-string API, disclosure authorization, transport, proof acceptance, analysis, publication, or external provenance claim is introduced.
Merged and exact-main-verified GH-121 applies the same isolated boundary to exact PE32 and PE32+ bytes. It fixes windows/pe scope, caps parsing at 16 MiB, 4096 import descriptors, and 4096 thunk entries, rejects ordinal and grammar-invalid imports, and byte-sorts/deduplicates named functions before checked selection. Rust covers both PE architectures while Python independently parses a synthetic shared PE32+ vector. Library names never become observables, every output remains local-only review_required_v1, and no path/string/generic, transport, proof, analyzer, wallet, chain, or promotion behavior is introduced. Protected PR #122 is merged as exact-main 2e3e1e1; CI, Security, and Pages pass on that SHA.
Merged and exact-main-verified GH-107 adds matching local Rust/Python verification of one canonical, short-lived BIP340 approval statement for one exact review_required_v1 bundle. It binds a separately trusted approver key, recipient-scope digest, network, report nonce, and separately trusted current time that must never be attacker-controlled, recomputes the observable commitment, and caps inclusive validity at one hour. It contains no signer and triggers no replay persistence, transport, promotion, disclosure, analysis, publication, proof, wallet, or chain action. The nonce and deterministic approval ID identify repeats but do not prevent replay.
Merged and exact-main-verified GH-111 adds a local durable consumption boundary in Guardian Node. One owner-only exact-schema policy fixes the network, approver public key, and opaque recipient-scope digest. The service invokes the GH-107 verifier in the same trusted call path, then atomically consumes both the approval ID and authority-bound nonce in a separate owner-only SQLite ledger. Full synchronous durability, persistent clock high-water, and restart/concurrency/lock handling close local replay without accepting caller-supplied verified objects. The receipt grants no external authority and adds no pairing, promotion, transport, analyzer, outbox, proof, wallet, or chain action. Key ownership/rotation, scope semantics, privacy approval, and future side-effect semantics remain open.
Merged and exact-main-verified GH-114 adds isolated local Rust and Python parsers for one canonical ThreatHint v2 statement. The 1024-byte-bounded wire keeps artifact hash and observable commitment separate and binds them with confidence, structural disclosure class, report nonce, positive observed time, and a network that must match separately trusted local context. A new length-prefixed, domain-separated digest covers every canonical field, and one shared exact-byte corpus fixes valid and invalid behavior. This is structural binding only: no approved relation, proof, signer, pairing, replay authority, transport, analyzer, wallet, or chain path consumes it, and it proves no artifact derivation, report truth, maliciousness, privacy safety, authorization, or anonymity.
Merged and exact-main-verified GH-117, but not production-deployed, adds strict Rust/Python parsers for a bounded opaque-proof envelope and a 19-field RelationManifest-v2, plus one atomic data-only binding. A separately trusted network and raw-manifest SHA-256 are required before canonical reparsing; protocol, relation, network, statement-domain, and public-input identities are then closed and the statement digest is split into two claimed 16-byte big-endian halves. This is not Groth16 verification or artifact approval and adds no ceremony, signer, transport, analyzer, promotion, wallet, chain, reputation, KAS/PROM, slash, commit-reveal, or rollout authority.
Merged and exact-main-verified GH-117 adds silent verify-v2. It owner-loads exact manifest, relation-source, and verifying-key bytes, binds their declared sizes and SHA-256 anchors, accepts only canonical compressed BN254 keys and proofs, derives both field inputs only through the reviewed v2 binding, and performs real Arkworks Groth16 verification. Runtime loads no proving key. Its generated relation, keys, and proofs are test-only; no production artifact or ceremony is approved and no privacy, approval-consumption, transport, chain, or rollout authority is added.
Merged and exact-main-verified GH-117, but not production-deployed, adds an owner-only read-only ThreatHint v2 privacy/proof preflight. Its exact policy pins the network, BIP340 approver key, opaque recipient scope, and raw-manifest SHA-256. Guardian Node derives the statement only from the bound envelope, recomputes the review-required bundle commitment against the same trusted nonce, and verifies the short-lived approval. It verifies no Groth16 proof, consumes no approval, opens or migrates no SQLite ledger, and authorizes no privacy, disclosure, transport, analysis, promotion, wallet, chain, or rollout action.
Merged and exact-main-verified GH-117, but not production-deployed, composes those checks in one POSIX-only Guardian call without making them authoritative. Owner-only configuration pins an absolute verifier executable and exact SHA-256; the existing policy remains the sole network and manifest anchor. Guardian runs the approval/privacy preflight first, then passes the same exact envelope bytes to a bounded, scrubbed, shell-free verify-v2 process. Its non-constructible, non-serializable receipt is data only. This layer deliberately opens no SQLite ledger and consumes no approval; the separate merged atomic-acceptance boundary below adds that final mechanical step. Neither layer grants production artifact, privacy, disclosure, transport, analysis, promotion, wallet, chain, or rollout authority.
Merged and exact-main-verified GH-117, but not production-deployed, accepts raw envelope, bundle, and approval bytes only and requires exact network, approver-key, and recipient-scope identity across preflight and consumption policy before ledger creation. It runs verified proof/privacy preflight first, then re-verifies the approval ID and observable commitment before durable consumption executes as the final state-changing step. Failed verification never consumes or advances ledger time; the receipt remains non-constructible, non-serializable data only. Production relation/key/ceremony approval, independent cryptographic review, privacy promotion, transport, analysis, signing, chain effects, and rollout remain separate gates.
Merged and exact-main-verified GH-117, but not production-deployed, adds an owner-only exact-schema promotion boundary above atomic acceptance. It requires review-required disclosure, exact platform and format, allowed observable kinds, and a bounded count before the same original raw wires may enter verification and consumption. The policy is opened no-follow through an identity-checked bounded descriptor; rejection never reaches the verifier or ledger. Success is restricted local data only. This closes mechanical local pairing and owner-policy restriction, not semantic per-kind privacy review, authority/key governance, production artifact approval, transport, analysis, publication, external effects, chain authority, or rollout.
Merged and exact-main-verified GH-117, but not production-deployed, makes the authority and privacy policy enforceable across promotion, retention, proof precheck, and durable consumption. One exact owner policy fixes network, approver, recipient scope, authority epoch and window, same-Guardian local-analysis semantics, denied external disclosure, and one deny-or-risk-specific decision for every observable kind. All three policy kind sets must match. First valid use atomically pins all three exact policy-file digests and authority state; stale epochs, same-epoch changes, overlapping same-identity windows, replay, and failed inserts change no durable state. This is local enforcement only and grants no worker, transport, actionable analysis, publication, chain action, or production relation/key/ceremony approval.
Merged and exact-main-verified GH-117, but not production-deployed, advances the governed queue to schema v4. The same BEGIN IMMEDIATE transaction stores the canonical statement and digest, trusted report nonce, full Observable Bundle, approval binding, authority state, replay high-water, and retention. Claims revalidate every binding and derive a lease-bound input identity. Atomic completion stores one canonical explicitly non-actionable result before deleting work and supports exact idempotent retry. Empty schema-v3 queues migrate; nonempty v3 queues fail closed unchanged. The bounded worker uses only a deterministic test analyzer and adds no confidence, should_submit, LLM, YARA/rule body, semantic finding, transport, disclosure, wallet, signature, transaction, chain, reward, deployment, or external effect.
Merged and exact-main-verified GH-152, not production-deployed, advances governed ledgers to schema v5 with one permanent strict one-to-one-to-one binding of the exact statement digest, approval ID, and observable commitment in the same atomic promotion transaction. Fresh approvals cannot rebind accepted statements or commitments, and outbox/result retention cannot reopen replay. A v4 ledger migrates only when its outbox and result tables are empty; authority, replay high-water, and approval-consumption state are preserved. Any retained v4 outbox or result row fails closed unchanged. This adds no proof, privacy, analysis, transport, disclosure, wallet, chain, reward, deployment, or production authority.
Merged and exact-main-verified GH-167 adds the bounded ThreatHint-v2 repository transport substrate without enabling production. Rust and Python share one exact canonical transport frame and valid/invalid corpus for the proof-envelope, Observable Bundle, approval wire, and untrusted report-nonce lookup key. The independent /prometheus/threat-hint/2.0.0 channel reparses inbound bytes against an explicitly trusted local network before owner-only IPC; the Python boundary reparses again, resolves the nonce only through trusted active-session state, obtains trusted time locally, and then calls the existing governed promotion path with the original wires. Global budgets, accepted/rejected/busy acknowledgements, adversarial tests, and separate-process same-host evidence are included. PR #168 published exact main 7c62608; Prometheus CI 31645624623, Security Audit 31645624601, and Pages 31645623547 pass. Production proof artifacts, semantic/actionable analysis, disclosure, public multi-host operation, LLM/YARA, wallet, chain, rewards, and deployment remain outside this boundary.
Merged and exact-main-verified GH-155 hardens Guardian sidecar process integration tests by serializing shared cases, bounding diagnostics and waits, coordinating collector EOF/ACK shutdown, holding the relay-port reservation until spawn, and deterministically killing and reaping a real child on timeout. PR #156 published exact main db33f56; CI, Security, and Pages pass after 20 consecutive stress runs and complete review. This is test-infrastructure evidence only and changes no protocol, production behavior, H-001 readiness, core-rollout percentage, or roadmap percentage.
Three target layers. Trust assumptions explicit.
The target anchors canonical rule state and a CID on Kaspa L1 while rule content lives on IPFS. The current RuleStorage gate verifies CIDv1, quorum, and submit/vote/finalize/deactivate transitions; PROM-RULES orchestration remains deployment work. Anchoring can expose state/CID tampering, but does not guarantee IPFS availability, replication, or universal censorship resistance.
- DAGKnight consensus: Adaptive, parameterless consensus with theoretically optimal Byzantine fault tolerance (~50%). Converges under attack orders of magnitude faster than classical systems.
- BlockDAG architecture: Parallel block production eliminates the bottleneck of linear chains. Prometheus treats high throughput as a deployment requirement and verifies contract/tooling compatibility before launch.
- Silverscript: High-level language for UTXO-based smart contracts. H-001, ValidatorStaking, GuardianReputation, RuleStorage, CommunityDonations, DevIncentivePool, and GovernanceAutoTuning current-Silverc gates are verified. Closed release-manifest profiles separate the single H-001 testnet-10 canary from the full seven-fixture flow; the confirmed canary receipt and independent evidence remain deliberately non-promotable. Release-bundle, deploy-preflight, request/procedure/receipt/evidence verification, operator-handoff, metrics-oracle, and exact-commit hardening gates are covered; the six remaining state deployments, oracle evidence, production proof artifacts, and release evidence still gate Prometheus rollout.
- Keyless genesis operator: Prometheus constructs the official transaction-v1 covenant genesis with compute budget 10 and exact contextual storage mass, validates the exact live funding UTXO during preflight and again before broadcast, and exports only the public sighash to an external vault/HSM. Its canonical import accepts only a public 64-byte BIP340 signature as lowercase hex, binds all response fields from the validated request, rejects normalized input/output path collisions, and verifies BIP340 plus the complete transaction before writing output. It enforces fee caps, journals the exact transaction before acknowledged submission, reconciles retries against chain and mempool state, and rebuilds the signed transaction before observation. A funding-free probe uses the pinned public resolver with mandatory TLS and testnet-10-only enforcement, recording the resolved endpoint without replacing funding or independent-evidence gates. Per-request wRPC deadlines fail closed. The CLI accepts no private key, seed, wallet, keystore, password, or raw transaction.
- Native ZK verification: Kaspa KIP-16 supplies BN254 Groth16 verification. Prometheus has a manifest-pinned verifier engine, but no approved production relation or keys ship yet. The exact circuit determines what is proved; v1 does not establish artifact derivation, report truth, or reporter anonymity.
Prometheus does not depend on Kasplex or any third-party L2 for Guardian reputation. Canonical Guardian reputation lives on Kaspa L1. Optional L2 or off-chain services may later aggregate analytics, dashboards, or reward views, but they cannot override the L1 source of truth.
The merged and exact-main-verified GH-42 carrier uses bounded direct QUIC request/response at /prometheus/guardian-ballot/1.0.0. It transports one exact canonical signed ballot of at most 8192 bytes, forwards it through an owner-only Unix socket to the existing BIP340/session/replay verifier, keeps swarm progress cancellation-safe during concurrent collector work, and returns only a digest-bound accepted, duplicate, rejected, or busy result. Merged and exact-main-verified GH-44 adds atomic owner-only persistent transport identity, strict bounded IP/UDP/QUIC-v1 direct, relay-circuit, and AutoNAT routes, data-minimal health events, and a bounded relay service. Merged and exact-main-verified GH-48 packages guardian and relay roles as an operated binary with strict owner-only TOML, bounded local submission, bounded JSON readiness/health, and graceful signal drain. Merged and exact-main-verified GH-52 separates relay bind listeners from explicit canonical advertised IP/UDP/QUIC bootstrap routes and emits path-free routes bound to the persistent transport peer ID. Merged and exact-main-verified GH-55/GH-58/GH-63/GH-74 provide the independent canonical 2048-byte-bounded ThreatHint channel, owner-only durable verifier ingress, a real manifest-pinned BN254/Arkworks Groth16 engine aligned with active KIP-16, and the bounded analyzer adapter. Merged and exact-main-verified GH-77 isolates per-job drain failures: failed jobs remain pending, later safe jobs progress, and the structurally immutable report contains only a bounded index, fixed failure category, and validated digest or none. Merged and exact-main-verified GH-86 adds local-only Rust/Python canonical Observable Bundle validators and one shared byte-exact corpus without wiring them into v1, proof, transport, analysis, or publication. Canonical outbox bytes, digest, trusted network, proof mode, and admission time are revalidated, but hash-only v1 contains no concrete IOC strings and therefore yields only a zero-confidence, no-rule, non-submittable result without invoking LLM or YARA generation. No approved production relation or production relation vectors, verifying key, or proving key ships yet, so unavailable verification remains fail-closed as busy and actionable analysis is not claimed. Peer IDs, addresses, relays, and routes remain transport metadata and never Guardian or reporter authorization.
A deterministic isolated three-node harness proves relay reservation, relay-only ballot and ACK delivery, AutoNAT state, DCUtR failure with continued relay fallback, and circuit/connection close handling. A separate-process same-host test additionally proves exact relay delivery from the local submit socket to the collector, canonical ACK propagation, SIGTERM cleanup, and stable transport identities. Real two-host relay/NAT operation remains open. Broad discovery is not yet proven, and mDNS stays excluded while its compatible optional DNS dependency path has unresolved RustSec advisories.
The actual protective effect arises off-chain on user devices and operator nodes. Local scanning is designed to keep files and paths on the originating device, while bounded claim metadata and future explicitly reviewed observables may cross protocol boundaries.
Why Kaspa? Kaspa is the only Proof-of-Work blockchain that fulfills the technical requirements of Prometheus: sub-second finality, 100+ BPS, Silverscript for native L1 contracts, ZK-proof support on L1, and a 0% pre-mine philosophy identical to Prometheus.
Four target roles. Operation remains gated.
| Node Type | Hardware | Role | PROM Share |
|---|---|---|---|
| Light Client | 4 GB RAM, no GPU | Target: local detection and data-minimal, precisely proved reporting | 15% |
| Guardian Node | 24 GB NVIDIA GPU (8B) or 4× A100/H100 80 GB (70B) | LLaMA 3 analysis, YARA rule generation, reputation-based voting | 30% |
| Validator Node | Standard server + 10,000 KAS stake | Commit-Reveal voting, economic security, slashing enforcement | 40% |
| Honeypot Node | Any internet-exposed server | Zero-day detection via decoy services | 5% |
LLaMA 3 70B requires 4× NVIDIA A100/H100 80 GB GPUs and substantial host memory. This excludes many potential Guardian operators. The unquantized LLaMA 3 8B profile still runs on one 24 GB consumer GPU, lowering the entry barrier without promising unsupported 12–16 GB operation. The implemented local router runs 8B first and escalates to an independent 70B analyzer below confidence 0.70. Invalid confidence, mismatched threat hashes, malformed submission decisions, or a failed 70B route fail closed. The network submission threshold remains 0.85.
The local YARA generator now obtains source confidence through a separate bounded model call. It accepts exactly one closed JSON object with an integer confidence_bps value from 0 through 10000; malformed envelopes, duplicate or extra keys, non-integer values, and out-of-range values fail closed. Indicator count and YARA text shape no longer set the score, and the accepted basis-point value is preserved through ensemble commitments without a float round trip. This validates response format only. Live model wiring, adversarial quality evaluation, calibrated confidence, and production evidence remain open.
GH-138 adds a standalone deterministic development evaluator over a canonical 24-case synthetic YARA corpus, exact integer-bps predictions, a fixed policy, an expected report, and a co-versioned SHA-256 consistency manifest. Its byte-exact output measures the unchanged 8500-bps confusion matrix, exact-ratio precision and recall, Brier score, and fixed ten-bin expected calibration error. Missing, duplicate, reordered, noncanonical, weakened-policy, or internally hash-inconsistent evidence fails closed. This catches partial fixture drift inside one reviewed revision. It is neither signed nor externally anchored, so it does not provide independent tamper evidence. The committed evidence is synthetic offline CI only and explicitly grants no production authority; live-model semantic quality, real adversarial robustness, production calibration, and authorization remain open.
Merged and exact-main-verified GH-141 adds a separate local candidate boundary. The canonical cases can be scored only through a literal-loopback vLLM service with environment proxies disabled. One closed-schema score per case is captured into an atomic owner-only prediction file bound to the corpus, public served-model identifier, caller-supplied model-artifact digest, and pinned prompt specification. Offline verification reports local_model_candidate_only and always records production_authorized=false. No live result is committed, and the tool does not independently prove artifact provenance, semantic accuracy, prompt-injection robustness, calibration, or production authority. Protected PR #142 squash-merged normally as exact main bf3f74f; CI, Security Audit, and Pages pass on that SHA.
Merged and exact-main-verified GH-161 adds a preferred owner-local provenance mode without granting authority: every exact regular file in one bounded trusted-owner model directory is hashed into a canonical sorted manifest; a symlink root plus symlink, writable, or special tree entries, duplicate inodes, excessive inputs, and detected mid-scan mutation are rejected; and the directory is re-hashed before constructing the local model adapter. The resulting prediction header is bound to the SHA-256 of the exact manifest bytes. The original caller-supplied digest remains explicit legacy compatibility. This establishes local disk-byte consistency only; it does not authenticate the upstream source, approve the model, or prove that an already running vLLM service loaded those same bytes. Protected PR #162 merged as exact main d468426; CI 31340112225, Security Audit 31340112204, and Pages 31340111625 pass.
Merged and exact-main-verified GH-144 hardens that local serving boundary without claiming a model run. It pins the official vLLM image by release and registry digest; provides an 8B default and opt-in 70B profile; publishes only on literal host loopback; requires caller-provisioned read-only weights in forced offline mode; and runs non-root on an internal network with bounded processes, memory, shared memory, temporary storage, and logs. A structured repository gate rejects mutable images, remote or writable model sources, unsafe ports, privileges, secrets, missing resource limits, and profile or GPU drift. Protected PR #145 merged as 95d05cc; CI 30858991436, Security 30858991557, and Pages 30858990507 pass. No image or model is downloaded, no inference is executed, and no artifact provenance, semantic quality, calibration, or production authority is established.
The local Sprint 10B ensemble validator binds protocol version, threat hash, exact YARA bytes and metadata, source confidence in integer basis points, policy hash, and the pinned 8B model artifact into a domain-separated candidate digest. A committed snapshot requires at least five unique Guardian IDs and a membership-source digest. Every member must cast exactly one fully bound vote; approvals require at least 8500 basis points, a complete ballot requires a strict majority, and final confidence is the minimum of the source rule and all approvals. Any missing, duplicate, unknown, malformed, mismatched, tied, or below-policy input returns no submittable rule.
The GH-39 authenticated intake binds each Guardian ID to one exact BIP340 x-only public key inside a per-candidate and per-network session. Strict canonical envelopes commit the complete vote, nonce, and validity window; signatures are verified before an owner-only SQLite ledger atomically consumes one vote per member and one nonce per active session across restarts and concurrent submissions. GH-42 carries those exact bytes over bounded direct QUIC/libp2p request/response and an owner-only local collector bridge; merged GH-44 adds persistent transport identity and isolated relay/NAT evidence; merged and exact-main-verified GH-48 adds operated process packaging without changing trust. It does not establish trusted membership or key assignment, prove public or multi-host relay/NAT operation or broad discovery, prevent Sybil identities, submit proposals, attest the ensemble on Kaspa L1, or include production private-key handling.
Merged and exact-main-verified GH-147 defines the source behind that snapshot and signer mapping. One exact schema-v1, network-bound and epoch-labelled canonical JSON document binds 5–1024 sorted unique Guardian IDs one-to-one to structurally valid public BIP340 x-only keys, fixed 8b model tier, and model-artifact digests. SHA-256 is computed over the exact source bytes. Parsing rejects malformed, duplicate, missing, extra, reordered, noncanonical, shared-key, and wrong-network input; a POSIX-only loader additionally requires an owner-only, no-symlink, bounded, descriptor-verified file. The validated source derives the existing snapshot and signer types without changing them. Protected PR #148 squash-merged normally as exact main aeecffb; CI 30863940497, Security 30863940502, and Pages 30863940053 pass.
GH-242 composes that source with local authenticated ballot intake. The operated establishment call accepts an owner-only source path plus a separately trusted network and expected epoch, loads the source once, derives the existing snapshot and public BIP340 signer map internally, and registers the unchanged ballot session. It accepts no caller-supplied committee, signer map, snapshot, source digest, or context; direct context construction and public arbitrary registration are disabled. Epoch is an identity pin only, not time, freshness, rotation, finality, source authority, or chain state. PR #243 merged normally as exact main 5cb132c670d1e7771ccaf6dab2ddf5b1a6fd905a; exact-main CI 33433012614, Security Audit 33433012605, and Pages 33433011653 pass. This is merged repository evidence, not externally trusted membership, key ownership, Sybil resistance, L1 attestation, multi-host operation, or production authority.
Merged and exact-main-verified GH-246 adds owner-pinned membership continuity. An exact owner-only policy pins the network, one public BIP340 transition key, bootstrap source identity and SQLite ledger. Canonical signed transitions bind exact previous/next source digests, a strictly advancing epoch, bounded validity and nonce. The ledger atomically stores current canonical source bytes plus clock, epoch, replay and equivocation high-water. New ballot sessions derive only that current source while the same transaction lock is held. This public-verification boundary contains no signer/private-key path and proves no external authority, key ownership/rotation, Sybil resistance, L1 attestation, public multi-host operation, deployment or production trust. PR #247 squash-merged normally as exact main f12e821bb492caae3b94e5b3c882488eb7f2982d; CI 33452085421, Security Audit 33452085419, and Pages 33452084065 pass.
Merged and exact-main-verified GH-253/PR #254 at 5920cb4bb737376977f762beb0d5e3108519c7a0 rotates that transition authority through an owner-local repository mechanism. The durable current key authorizes one gapless successor epoch and the proposed key independently proves possession under a separate BIP340 digest domain. Both signatures bind current membership, bounded validity and nonce; exact schema-v1 ledgers migrate transactionally to v2, replay and historic key reuse fail closed, and later membership transitions verify only the durable current key. Prometheus CI 34031999904, Security Audit 34031999907, and Pages 34031999575 pass. This owner-local mechanism contains no signer/private-key path and proves no real-world key ownership, external/decentralized authority, Sybil resistance, L1 attestation, deployment or production trust.
This proves local structural and key-assignment consistency only. It does not establish who may author or trust the source, prove key ownership or rotation, prove public or multi-host operation or broad discovery, prevent Sybil identities, submit proposals, attest the ensemble on Kaspa L1, or include production private-key handling.
Open source models. Security specialization. Federated learning.
The choice of AI model is a security question, not a quality question. Proprietary models (GPT-4, Claude, Gemini) are black boxes — nobody can verify what they actually do. For a security system with transparency as a core principle, they are structurally unsuitable.
Target architecture: Microsoft's Phi-3-mini 3.8B runs locally on the end user's device for inference. Reporting and model-update paths remain separate, bounded data flows. The planned model is 4-bit quantized and targets ONNX Runtime on 4 GB RAM without GPU on Windows, macOS, Linux, and mobile; production inference is not yet wired.
GH-220 adds deterministic integer triage over exact bounded caller bytes and an owner-local digest-verified byte vault as Development foundations. The triage reports structural reasons only and has no malware or quarantine authority. The vault accepts no source path, never moves or deletes source files, and performs no automatic isolation. Neither component is production endpoint-security evidence.
GH-223 hardens the older Phi-3 wrapper into a 16 MiB-bounded fail-closed safe-default stub. Merely configuring an existing file cannot report a loaded ONNX model, and the stub emits no suspicion, malware verdict or quarantine authority. Real inference and real-sample evaluation remain open.
Merged and exact-main-verified PR #227 published exact main 6c39af5; Prometheus CI 32675287618, Security Audit 32675287530, and Pages 32675287300 pass. GH-226 adds one Development-only v1 ThreatHint sender to the real Light Client binary. It reuses the Guardian P2P stack in dial-only mode and accepts one static literal-loopback QUIC peer under strict owner-only files, offline preflight, exact canonical bytes, a 1–60 second bound, and redacted accepted/duplicate/rejected/busy/transport-failure outcomes. Same-host binary/QUIC/Guardian tests are engineering evidence only. Beta and Mainnet reject before network activity, and no proof, membership, public multi-host, wallet, chain, reward, deployment, or production authority is added.
Merged GH-229/PR #230 at exact main fba8bb4 provides the tested capability for one controlled Development/Testnet-10 direct-QUIC run; exact-main CI 33017195813, Security Audit 33017196184, and Pages 33017194744 pass. At 2026-08-26T23:36:04Z (2026-08-27 operator-local), one operator-attested run from source commit 27e8b02 delivered one canonical hint between two distinct controlled hosts. Sender and Guardian both recorded non-authorizing rejected, with zero retries, no persistence and acknowledgement authority none. The temporary sender-restricted UDP rule was removed immediately. The redacted evidence does not independently prove host separation. It is not public-network or relay/v2 evidence and adds no proof, membership, privacy, model/YARA, chain, reward, deployment, Mainnet or production claim.
Merged and exact-main-verified GH-234/PR #235, code commit b450740, exact main f146fb2, adds one separate Development/Testnet-10-only Light Client command for an owner-prepared canonical shared ThreatHint-v2 transport payload. It reparses the payload against separately trusted testnet-10 before identity or networking and sends exactly once over the existing Guardian v2 channel. Local unit and real same-host binary/QUIC tests cover offline preflight, accepted/rejected/busy/transport-failure, redaction, Beta/Mainnet gates and unchanged v1 behavior. Exact-main CI 33272578070, Security Audit 33272577951, and Pages 33272577407 pass. The client neither generates proofs nor verifies production approval authority, and this is not public/multi-host v2, deployment, Mainnet or production evidence.
Merged and exact-main-verified GH-238/PR #239, exact main 912d96d, implements and locally tests repository-only preparation for one later controlled distinct-host Development/Testnet-10 ThreatHint-v2 attempt. The tooling uses challenge-bound, role-specific operator attestations over the source commit, the actual executable digest, the exact canonical payload digest, the exact v2 protocol, one shared observed UTC time, the actual rejected status, one attempt, zero retries and no persistence, with strict owner-only/no-symlink files, the exact 9,265-byte Rust wire bound, atomic no-clobber record output, a closed redacted verifier and CI test wiring. Exact-main CI 33279351831, Security Audit 33279351822, and Pages 33279351387 pass. No real GH-238 remote run has occurred and no GH-238 evidence record exists; host separation is not independently proven. This repository preparation is not a deployment or remote demonstration and adds no port, firewall, host, IAM, wallet, chain, deployment, Mainnet or production action or authority; a later real run requires separate explicit authorization.
GH-258 and its GH-261 clarification define a future track for coordinated endpoint compromise, including attacks that may be AI-assisted or highly automated. This includes unauthorized compute conscription of endpoints, accelerators, servers or data-center capacity into a distributed mesh. Prometheus would reason from observable process/resource ownership, unexpected CPU/GPU workload, scheduler/orchestrator drift, workload-identity, persistence, credential-access, outbound fan-out, model/runtime-integrity, agent tool-policy and bounded cross-device correlation signals. Those signals cannot reliably identify a superintelligence or attribute an event to AI, AGI, a specific actor or intent.
The target stages are observe-only, warn-only, operator-confirmed reversible containment, and only later separately approved limited automation. Independent real-sample and adversarial evaluation, measured false positives, privacy review, multi-host evidence, rollback drills, signed policy/rule provenance, resource controls and explicit per-action authorization are mandatory gates.
This is target architecture only. No real-time endpoint sensor or response engine is implemented. Automatic process termination, quarantine, firewall mutation, credential rotation, remote commands, deletion and host isolation are disabled and unauthorized. GH-258 adds no contract emergency stop and changes no KAS/PROM, reputation, slashing or Commit-Reveal behavior.
GH-264 is the first repository implementation beneath that roadmap: Rust and Python share one canonical 512-byte observe-only statement with seven closed domains, 15 domain-bound signals, bounded counts/windows, an opaque nonce, minute-granularity time and a separately trusted network. It accepts caller-supplied bytes only and has no free-text or host-identifying fields. It collects no telemetry and proves no event truth, maliciousness, provenance, privacy safety, AI/actor attribution or authorization. It adds no sensor, correlation, warning, transport, response authority or production behavior.
The Guardian target uses LLaMA 3 8B first with optional 70B escalation. Hardened local runtime configuration and evidence-capture machinery exist, but no completed fine-tuning, real 8B/70B inference run, real-sample evaluation, calibration, or production authorization is proven. Planned inputs include:
- VirusShare: Largest public malware database, millions of samples
- MalwareBazaar: Current malware samples, daily updated
- Exploit-DB: Complete exploit database for CVE correlations
- CuckooSandbox Reports: Behavioral analysis of malware in sandbox environments
# LoRA Fine-Tuning Configuration
lora_config = LoraConfig(
r=16, # Rank
lora_alpha=32, # Scaling factor
target_modules=['q_proj', 'v_proj'], # Attention layers only
lora_dropout=0.1,
task_type='CAUSAL_LM'
)
# Only 1-5% of parameters are trained → efficient
# Training on ~500k malware samples
# Result: specialized security model on LLaMA 3 base
Target architecture: Fed-DART enables clients to train locally and exchange bounded model updates instead of raw training records. Model updates can still leak information through inference or reconstruction attacks, so clipping, aggregation, privacy accounting, authentication, and independent validation remain production requirements.
Privacy boundary: Sending gradients instead of raw records reduces direct disclosure; it does not make reconstruction impossible. ZK privacy and anonymity claims are limited to the exact reviewed circuit and surrounding transport.
Six Silverscript contracts. Deterministic state transitions.
The legacy contracts are written in Silverscript and use fixed-point integer scaling for reputation and confidence values (no float64). Current Silverc deployment fixtures use signed entrypoint integers at the deploy boundary; deployment calls are scoped to 0..=i64::MAX where numeric values enter Silverc.
| Contract | Purpose | Key Functions |
|---|---|---|
| ValidatorStaking.ss | KAS staking + consensus voting | register, commitVote, revealVote, slash, withdraw |
| GuardianReputation.ss | Reputation + quadratic voting | register, voting_power, proposal_accepted/rejected |
| GovernanceAutoTuning.ss | Weekly parameter adjustment | auto_tune, get_parameter |
| DevIncentivePool.ss | DAO-voted developer rewards | proposeGrant, vote, executeGrant |
| CommunityDonations.ss | Transparent community fund | donateKas, proposeDisbursement |
| RuleStorage.ss | Rule state + target PROM-RULES asset orchestration | submitProposal, voteOnProposal, finalizeProposal |
Current-Silverc gates: All seven contract compile/ABI/runtime paths pass through the pinned compiler. Keyless requests are bound to deterministic release artifacts and independently verified. The repository operator enforces transaction v1, exact compute and contextual storage mass, compiled-script P2SH, official covenant binding, live UTXO validation, digest-only external BIP340 signing, complete input execution, acknowledged broadcast, and covenant-output observation. The reportMetrics path additionally preserves state value exactly and uses a separate P2PK fee sponsor with its own external signature. Public receipts, node/explorer evidence, status staging, operator capability, and exact-commit release-hardening gates remain separate so fixtures cannot become rollout evidence.
CRITICAL — KAS/PROM separation: Validators stake KAS (tx.value = KAS, constant = MIN_STAKE_KAS = 10,000). PROM is earned by Guardians through accepted proposals — never staked by Validators. Confusing the two tokens is the most common implementation error (PATTERN-001).
Two tokens. No shortcuts.
| Token | Role | Source | Value basis |
|---|---|---|---|
| KAS | Validator staking + slashing | Kaspa network (existing asset) | Kaspa network usage, $1B+ market cap |
| PROM | Rewards + governance | Earned through accepted security work (0% pre-mine) | Utility in Prometheus ecosystem |
| Year | Emission | Validators 40% | Guardians 30% | Reporters 20% | Dev Pool 5% | Community 5% |
|---|---|---|---|---|---|---|
| Year 1 | 20,000,000 | 8,000,000 | 6,000,000 | 4,000,000 | 1,000,000 | 1,000,000 |
| Year 2 | 18,000,000 | 7,200,000 | 5,400,000 | 3,600,000 | 900,000 | 900,000 |
| Year 3 | 16,000,000 | 6,400,000 | 4,800,000 | 3,200,000 | 800,000 | 800,000 |
| Year 5 | 12,000,000 | 4,800,000 | 3,600,000 | 2,400,000 | 600,000 | 600,000 |
| Total | 80,000,000 | 32,000,000 | 24,000,000 | 16,000,000 | 4,000,000 | 4,000,000 |
These are predefined allocation targets, including Dev Pool 5% and Community 5%, not active emissions. Primary contribution issuance and a later KAS/PROM secondary market are planned; minting, deployment, liquidity, and trading are inactive.
Specified launch allocation: 0% pre-mine, ICO, presale, founder, or foundation allocation. This does not mean no allocation exists; the participant, Dev, and Community pools above total 100% of planned emission.
Economic security through KAS staking.
Validator state machines use KAS staking, never PROM, with tested quorum, bond, Commit-Reveal, and slashing transitions. No operated validator network, trusted decentralized membership authority, or production quorum is proven.
| Property | Value |
|---|---|
| MIN_STAKE_KAS | 10,000 KAS (dynamic via auto-tuning) |
| Slashing — simple | 5% KAS loss |
| Slashing — double vote | 10% KAS loss |
| Slashing — collusion | 20% KAS loss |
| Escalation | multiplier = min(3, slashing_count / 3 + 1) |
| Cooldown | 7 days (100,800 blocks at 10 BPS) |
| Bond per vote | 10% of current stake |
| Access control on slash() | Only GOVERNANCE_CONTRACT or RULE_STORAGE_CONTRACT |
Reputation capital through AI contribution.
Guardian interfaces target model-assisted analysis and rule proposals. Current evidence covers runtime scaffolding, compile-valid syntax, a non-actionable draft, and synthetic regression only. Real-model quality and actionable authority remain blocked.
| Property | Value |
|---|---|
| REPUTATION_START | 1,000 (= 0.1 at 10,000× scale) |
| MIN_REPUTATION | 1,000 — below this: voting rights revoked |
| On accepted proposal | reputation += sqrt(compute_power) × 100 |
| On rejected proposal | reputation × 0.5 (halving) |
| Voting power formula | (reputation / 100)² × compute_power / 1,000 |
| Anti-Sybil | PoW registration + quadratic voting |
| Model eligibility | ≥ 500 GFLOPS may serve 70B escalation; all hybrid routes start with 8B |
Guardian reputation is canonical Kaspa L1 state in GuardianReputationState. It is separate from PROM balances and is not a badge or NFT.
Commit-Reveal. Bond system. 67% quorum.
The tested Commit-Reveal state machine is designed to reduce vote copying. It does not by itself prove collusion resistance or operation by a decentralized validator network.
# Phase 1: COMMIT — validator sends only a hash # commitment = sha256(vote_byte || salt_LE || block_height_LE) # vote_byte: 1 = true, 0 = false # salt and block_height as 8-byte little-endian # Phase 2: REVEAL — after 10-second collection phase # Validator reveals actual vote + salt # Network verifies: sha256(vote||salt||block) == commitment # Invalid reveal → bond slashed immediately
This formula is identical in Silverscript contracts and Rust implementation. Cross-verification tests ensure bit-for-bit identity between the contract and the validator node code.
CIDv1 rule state. Asset representation gated.
Each accepted rule is anchored as canonical state on Kaspa L1. The product target is a unique PROM-RULES asset representation, but the verified current-Silverc gate intentionally covers the rule state machine first:
- Target tick: PROM-RULES
- Target supply: 1 per accepted rule
- Target ID format: PROM-RULE-2026-XXXX
- IPFS reference: bytes(36) — CIDv1 binary with SHA-256 multihash (not bytes(46) — corrected in audit V-002)
- Minimum confidence: 0.85 (stored as 8,500 at 10,000× scale)
- Current gate: RuleStorageState verifies submit/vote/finalize/deactivate covenant sigscripts and Guardian reputation outcome events
The target stores rule content on IPFS and anchors its CIDv1 on-chain. deactivateRule is an explicit authorized transition. GH-190 adds development-only verification of bounded caller-supplied exact bytes against canonical Raw-CIDv1 plus atomic simple-matcher activation. Merged and exact-main-verified GH-197/PR #198 adds a separately owner-pin-hashed canonical Testnet-10 manifest check over bounded RuleStorage UTXO observations before exact constructor-state decoding. GH-203/PR #204 adds bounded development-only acquisition from one connected Testnet-10 node. GH-205 composes one complete owner-pinned snapshot through that injected/live observation, a credential-free loopback-only local IPFS gateway, repeated exact CID/content binding, and one atomic scanner replacement. GH-207 adds an owner-local POSIX checkpoint ordered by the minimum verified observation virtual DAA, with exact-identity digest binding, rollback/equivocation rejection, and restart exact-replay recovery. GH-209 adds bounded opt-in development orchestration. GH-211 adds one strict canonical BIP340-authenticated complete-snapshot envelope using a separately owner-pinned x-only key, external nonzero minimum sequence, and separately trusted clock rechecked on every fetch. Merged and exact-main-verified GH-213/PR #214 at bbe7efb adds an operator-invoked Development/Testnet-10 preflight/run CLI with private strict local files, offline non-mutating preflight, loopback-IP-literal RPC/IPFS, redacted status, and signal cancellation; CI 31950806131, Security 31950806118, and Pages 31950805653 pass. It adds no signer, key-authority/rotation proof, persistent sequence authority, autonomous provider, wallet, chain write, deployment, or Mainnet support. One signed owner-authorized snapshot envelope, one node and one local gateway do not establish independent RPC truth or history, consensus finality, canonical manifest authority, IPFS availability or replication, real YARA, censorship resistance, deployment, or production readiness.
Merged and exact-main-verified GH-216/PR #217 at 13c1812 adds test-only real-binary loopback E2E evidence for offline/connected preflight, private checkpoint commit, SIGTERM/SIGINT drain, restart exact replay, rollback/equivocation rejection, and malformed, timeout, or disconnected peers; CI 31978132036, Security 31978132044, and Pages 31978131647 pass. This is local Development evidence only, not public Testnet operation, independent RPC/IPFS truth or availability, deployment, Mainnet, or production readiness.
The network learns through bounded model updates.
Target architecture: Fed-DART keeps training records local and exchanges model updates. Those updates are not raw records, but they may still leak information; production requires clipping, secure aggregation, privacy accounting, authentication, and validation.
# Fed-DART Training Round (simplified)
async def training_round(self):
# 1. Fetch global model from coordinator
global_model = await self.client.fetch_global_model()
# 2. Train locally — ONLY with local threat data
local_gradients = await self.train_local(global_model)
# 3. Send bounded model updates; privacy controls remain required
await self.client.submit_update(ModelUpdate(
gradients=local_gradients, # Mathematical difference
client_id=self.pseudonymous_id(), # Not an anonymity guarantee
data_size=self.local_data_count,# Count, not content
signature=self.sign_update() # Authenticity
))
# 4. Aggregated global model is distributed
# No single client knows the data of any other
Deterministic, bounded auto-tuning.
Target behavior: authenticated metrics drive bounded weekly parameter transitions. The repository verifies deterministic state transitions, but real inputs, external signatures, confirmed successor evidence, and production operation remain gated. There is no repository-controlled emergency-stop entrypoint; availability still depends on Kaspa, nodes, clients, and network access.
| Parameter | Start value | Target |
|---|---|---|
| MIN_STAKE_KAS | 10,000 | 50–200 active validators |
| MIN_GUARDIAN_REP | 3,000 (= 0.3) | 200–1,000 active guardians |
| MIN_CONFIDENCE_KI | 8,500 (= 0.85) | False positive rate < 0.5% |
| VALIDATOR_CONSENSUS | 6,700 (= 0.67) | Stable rule acceptance |
| REWARD_BASE | 100 PROM | 100–200 proposals/day |
| CHALLENGE_PERIOD | 86,400s | 24 hours |
Sybil resistance. FP flood. 51% attack. Collusion.
| Attack | Countermeasure |
|---|---|
| Sybil attack | Quadratic weighting is implemented arithmetic, not proof of Sybil resistance; membership authority, key lifecycle, compute attestation, and on-chain attestation remain open. |
| Collusion | Commit-Reveal and bonds are tested state-machine mitigations; operated-network resistance is unproven. |
| False positive flood | Min. 85% confidence threshold. Only 5+ independent reports trigger Guardian analysis. |
| Model poisoning | On-chain hash verification is a target tamper check; provenance, authorization, quality, availability, and deployment remain open. |
| 51% attack | DAGKnight: ~50% Byzantine fault tolerance. Prometheus inherits Kaspa security. |
| Long-range attack | Weak subjectivity: new validators can only vote from their entry timestamp. |
| Emergency stop | No repository-controlled emergency-stop entrypoint is introduced. This removes a developer kill switch, not every availability dependency. |
Planned 5% Dev Pool. DAO vote required.
The specification reserves 5% of planned emission for developer grants and 5% for Community use. No PROM emission is active; no founder or foundation allocation is specified.
Recommended reward formula: lines × 10 × (100 + complexity × 10) / 100 — capped at 100,000 PROM per grant. Complexity scale: 1–10.
Before mainnet launch, no tokens are issued. Development is financed through external funding — Gitcoin Grants (quadratic funding, community-decided), Octant (matching pools for open-source infrastructure), and community donations in KAS.
Built in public. Audited in public.
| Phase | Timeline | Milestone |
|---|---|---|
| Foundation | March 2026 | Sprints 0–8 complete. 6 contracts, 160+ tests, landing page live. |
| Kaspa Toccata | June–August 2026 | Current-Silverc runtime/release gates and the keyless Toccata-v1 genesis operator are implemented. The closed, non-promotable ValidatorStakingH001 Testnet-10 canary completed external signature, operator verification, one-shot broadcast, network confirmation, a public operator_record receipt, and independent node/REST evidence on 2026-08-12. Full seven-fixture, production-proof, multi-host, oracle, and release-hardening gates remain. |
| Miner Companion | July 2026 | Experimental opt-in local Testnet-10 wRPC observer and strict preflight implemented. Scanning, reporting, rewards, validator/honeypot roles, Stratum integration, and miner firmware integration remain disabled. |
| AI Production | Readiness-gated | Approved proof relation/artifacts, v2 observable path, operated P2P, production Phi-3/LLaMA, and privacy-reviewed federated learning. |
| Desktop Release | Readiness-gated | Windows / macOS / Linux installers after core-network and security gates pass. |
| Mobile Release | Readiness-gated | iOS and Android follow the desktop/core security boundary; no fixed release date is claimed. |
| vProgs | Future research | AI-result anchoring requires a separately reviewed protocol and proof statement. |
All findings public. Deployment gates tracked.
All development is subject to continuous architect audit via the Claude Code workflow. Every finding is documented in memory/AUDIT.md and publicly visible in the repository.
| Finding | Severity | Resolution |
|---|---|---|
| V-001: float64 not supported in ssc | HIGH | uint64 with 10,000× scaling in all contracts |
| V-002: CID bytes(46) incorrect | HIGH | bytes(36) for CIDv1 binary SHA-256 multihash |
| V-003: Recursive slash() function | HIGH | Non-recursive: multiplier = min(3, count/3+1), applied once |
| FIX-001: slash() without access control | CRITICAL | ACL: only GOVERNANCE_CONTRACT or RULE_STORAGE_CONTRACT |
| FIX-002: .active() compile error | HIGH | Changed to registered_at == 0 |
| FIX-003: Cumulative FP counter | HIGH | Time-windowed counter (864,000 blocks = 1 day) |
| FIX-004: Bond not returned on reveal | LOW | transfer(msg.sender, vc.bond_kas) on valid reveal |
| FIX-005: Reward formula mismatch | LOW | Corrected to whitepaper formula |
| Legacy testnet baseline | INFO | kaspa-testnet-10 confirmed for March 2026 tests; post-Toccata current-Silverc gates now pass for H-001, ValidatorStaking, GuardianReputation, RuleStorage, CommunityDonations, DevIncentivePool, and GovernanceAutoTuning |
| Official PSKT v1 gap | HIGH | PSKT/PSKB is not used for Toccata genesis because its audited v1 path still creates legacy sigop-count commitments; the operator uses official compute-budget transaction APIs directly |
Total audit rounds: 10 · Sprint findings: 11 · Critical issues fixed; remaining deployment gates tracked before beta/mainnet. Full audit log: memory/AUDIT.md