privacy · proofs · compute
v2.0 · checksummed

§0. Introduction

v2.0
Cite this section

Copy/paste (plain text):

Jason St George. "§0. Introduction" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v2.0. /v/2.0/read/part-i/0-introduction/

Introduction

Start Here: Four Reading Paths

This chapter opens with the cultural and historical argument for why anchors are being sought at all. That framing matters, but it is not the load-bearing part of the thesis, and readers who already accept the premise should skip ahead rather than wade through it.

If you allocate capital or underwrite risk:
read the Executive Memo and Reader’s Map in the front matter, then §0: Introduction (the ten premises), §6: The Triad and the Monetary Candidate (the argument in one page, with its weakest links named), §10: Work Credits: Energy-Anchored Claims (the condition that decides whether any of this captures service value), §27: Risk Analysis & Failure Modes (the fifteen ways to prove us wrong), and §13: SoV Evaluation Framework (the evaluation questions to put to any candidate instrument).

If you build infrastructure:
start at §5: Layers of the Cypherpunk Stack for the seven layers, then §21: The Modular Stack for the twelve primitives and §21: The Modular Stack for the four reference applications. §28: Implementation Sketches for Builders is the 12–36 month build sketch.

If you are here to find the weak points:
§4: Threat Model states the boundary conditions we cannot engineer away, §30: Objections & Responses answers the strongest objections we know of—including the completeness objection in §30: Objections & Responses§29: The Closed Sovereign Stack concedes what a competent closed sovereign stack does better, and §6: The Triad and the Monetary Candidate rates our own argument link by link.

If you want the whole claim in one sentence:
Thesis in Plain Language, in the front matter.

One warning that applies to every path: nothing in this document treats price as evidence. The monetary claim is tested on protocol telemetry, and price is interpreted separately (§10: Work Credits: Energy-Anchored Claims, §23: Extended Telemetry).

Every monetary epoch begins with an argument about what is real. James Dale Davidson and William Rees-Mogg, in their seminal work The Sovereign Individual, argued that the decentralization of computer networks would erode centralized power, and that governments, in their death throes, would reach for more aggressive tools of control: capital controls, nationalization, outright authoritarianism.

The old guarantees (central banks, broadcast media, credentialed authority) no longer hold their shape under the pressure of digital networks and foundation models. They are under attack, not by a single conspirator, but by the physics of decentralization itself, which dissolves the monopolies that once defined our shared reality.

Marshall McLuhan saw an even deeper shift: the move from print, a one-to-many medium that centralizes narrative, to electronic networks, a many-to-many mesh that fragments it. A print-created reality is a centralized reality: he who controls the press, controls the narrative. This underwrote 20th-century monetary supremacy and global settlement currency backed by a monopoly on violence: the post-1971 US petrodollar.

In the 20th century, citizens got their singular cultural feed from The New York Times over breakfast, and later their dualistic, pseudo-antagonistic programming from CNN and Fox News. In the 21st, the internet (many-to-many) erodes this centralization of narrative. Take the network formerly known as Twitter: authoritarian regimes that attempt to censor information find it very hard to stop leakage. Within minutes, people with “smart” phones can produce a preponderance of evidence that either supports or invalidates the prevailing story.

But a countervailing force has arrived: AI. The quality of realistic generated content has crossed a critical threshold, approaching the asymptote of believability. Synthetic faces, voices, and scenes now compete with direct sensory experience.

This creates a world wealthy in symbols but poor in anchors: a sea of abstractions with no obvious way back to sensible shores.

So we look for new anchors.

Cypherpunk cryptography is the unifying answer: privacy by default, proof by construction, and compute that only gets paid when anyone can verify it. It replaces authority with protocols and gossip with receipts. In this frame, money is not a promise from a platform; it is what remains when verification is cheap and permission is irrelevant. Cypherpunks don’t ask for integrity; they instrument it. They don’t trust platforms; they price receipts. The triad is that credo made economic: privacy that preserves agency, proofs that travel, and compute that earns only when anyone can verify it.

Bitcoin’s SHA-256 puzzle mints digital scarcity by tying consensus to thermodynamic cost, and it is worth being exact about why that works: the work has no external buyer. Nobody outside the system wants a partial hash preimage, so nobody can subsidize it, mandate it, price it, or withdraw demand for it. The cost is therefore non-negotiable, and the money inherits that objectivity. The design direction explored in this thesis keeps what makes PoW legitimate (open admission and unpredictable leader election) but swaps the work function, so that the “lottery ticket” is earned by producing succinct, publicly verifiable receipts of compute somebody wanted. Miners win by attaching a proof that a market-demanded computation was done correctly.

A natural anchor workload is matrix multiplication. MatMul-PoUW constructions make verification asymptotically cheaper than naive production (for example, O(n2)O(n^2) verification vs. O(n3)O(n^3) multiplication) while keeping verifier overhead at (1+o(1))(1+o(1)) relative to the best-known randomized checker. That turns AI’s core primitive into verified FLOPs: a commodity unit anyone can check cheaply. Projects like Nockchain show the zk-PoW design space operating in the wild (fair-launch ethos, scope-minimized “dumbnet,” explicit issuance), illustrating that proof-carrying work can be wired into consensus without appointing gatekeepers. Keep the lottery; change the work. Make the prize a receipt the public can verify—and accept, in exchange, that the receipt has a buyer and the buyer has a jurisdiction.

Caveat: MatMul-PoUW constructions and useful-work consensus are promising research directions, not yet proven production monetary bases. The arXiv literature describes the optimal-security claim as a conjecture; deployment-grade engineering remains ahead. This thesis frames PoUW as the destination of a research program, not a shipping product.

Operationally, the goal is simple: bind useful work to the hash race without introducing trust.

Two deployable patterns are in scope:

  • (A) Hash-gated useful work. A SHA-family threshold confers short-lived eligibility; a block is valid only if it carries a PoUW artifact (e.g., MatMul proof or zk-proof) seeded by header randomness.

  • (B) Proof-first selection. Miners race to post useful-work receipts to a mempool; header entropy resolves ties and timing.

Both patterns must prevent precomputation (epoch seeds, commit-reveal), avoid closed-hardware dependencies, and expose verifier-light clients plus dispute/slash routes for junk artifacts.

When blocks routinely carry proofs that clear public SLOs and decentralization telemetry remains healthy (time-to-first-proof, top-N share, geo/ASN spread), block rewards bind issuance to capacity the world already buys: ZK proving, matrix multiplication, verified inference. So Privacy, Proofs, and Compute may begin to earn monetary premium—if the conditions outlined in this thesis hold.

State the cost of this at the outset, because it is real and it runs the other way. An external buyer of the work is a party who can be regulated, subsidized, or coerced, and whose demand can therefore be moved by something other than the resource cost of the work. That is precisely the exposure SHA-256 avoids by having no buyer at all, and it is why Bitcoin’s work function is the monetarily stronger construction. Proof-of-useful-work is not an improvement on it; it is a different trade—monetary objectivity exchanged for capacity relevance—made in the belief that the second is what a dense digital civilization will be short of. The trade is argued at full strength, against itself, in §30: Objections & Responses, and a reader who wants the concession before the argument should go there first.

The rest of this Part translates that intuition into claims, contributions, a threat model, and a layered architecture.

What Would Falsify This Thesis?

The store-of-value claim fails if any of the following persist without remediation: (1) verification becomes expensive or gated (VerifyPrice breaks); (2) refund safety fails on admissible corridors; (3) verification concentrates in a single hardware profile or jurisdiction; (4) telemetry is captured or becomes unverifiable; (5) fee coverage collapses and workload demand becomes purely speculative; (6) users can consume triad capacity without touching the native asset; (7) wrapper and custodial exposure grows while native usage stagnates; (8) physical infrastructure claims become unverifiable; (9) AI compute enclosure persists; (10) lawful privacy collapses socially; (11) verification affordability becomes a sovereign policy variable; (12) the capturable wedge falls below the protocol take; or (13) a native-collateral drawdown drives operator exit, declining Delivered Verified Capacity, released float, and unrecovered service SLOs. These are illustrative; the full set of fifteen red lines is developed in §27: Risk Analysis & Failure Modes.

Central Claims

In this thesis we argue:

  1. Post-Bretton Woods money relies increasingly on compliance infrastructure.

    As convertibility receded, taxation capacity, legal tender status, central-bank balance sheets, collateral rules, and the compliance perimeter became the practical support structure of fiat money. When compliance becomes weaponized and asset freezing becomes policy, neutral stores of value become necessary infrastructure, not ideological luxuries.

  2. Three cryptographic capacities may support a monetary candidate under measurable conditions.

    Privacy (censorship-resistant settlement that preserves agency), Proofs (portable attestations of computation and provenance), and Compute (useful work wrapped in succinct guarantees) are distinct services. They support a monetary candidate only if their service path remains stress-deliverable, their demand cannot bypass the candidate asset, and native holders warehouse its residual risk. They need not share one token.

  3. A modular stack can operationalize this triad.

    We propose four reference applications (private treasury & payroll, media provenance, verified inference, proof/compute procurement) built on twelve primitives, with verification asymmetry and VerifyPrice as the key economic metrics that turn proofs and verified FLOPs into commodities rather than platform IOUs.

  4. Verifiable machines (Layer 0) are essential for physical-world claims.

    For pure proof correctness, sound cryptography should tolerate untrusted provers. Layer 0 becomes essential when the claim includes facts about physical capture, energy use, machine identity, witness confidentiality, side-channel resistance, or useful-work fairness. Open or sampled hardware is not ornament; it is the base layer that makes physical-world claims credible.

In the rest of the thesis we make this concrete in modular form. Four reference applications exercise the stack (private treasury & payroll, media provenance & authenticity, verified inference as AI service, and proof/compute procurement), supported by a small toolkit of primitives: a proofs-as-a-library SDK (“PaL”) that compiles claims to proofs, a privacy-rails kit that executes non-custodial, refund-safe settlement over BTC\leftrightarrowZEC/XMR corridors, a minimal receipt schema (“PIDL”) that turns every proof or settlement into a portable artifact, neutral router logic that keeps useful-work markets open, and a VerifyPrice observatory that measures how cheap verification really is. Later sections develop these primitives and applications in detail; here we refer to them by name once the context is clear.

The overall thesis is simple: the reserve question is not answered by one object, and the assets that already answer parts of it are not superseded by this one. Alongside them, a dense digital civilization needs a triad of verifiable necessities: Privacy, Proofs, and Compute. Treat this triad as services that may support an associated cypherpunk base asset:

  • Privacy: the right to hold and move value without chokepoints (to preserve agency).

  • Proofs: cryptographic attestations of origin, integrity, identity, or computation (to crystallize truth).

  • Compute: useful work (ZK proving, matrix multiplication, verified inference) that applications demand and that blockchains can verify cheaply (to power intelligence).

These are not slogans. They are the cypherpunk stack distilled into services: what cannot be forged, what no one has to bless, and what everyone can check. They are scarce capacities the world may continually buy because life in a dense, digital civilization requires them. Each has its own economy. Whether one monetary asset should sit beneath all three is a hypothesis tested below, not a conclusion smuggled into the definition.

Institutionally, this is not just a design for another chain. It is a research and engineering agenda: a Bell Labs for proof-of-useful-work and the zk economy. Where the original Bell Labs turned Shannon’s information theory into cables, switches, and semiconductors, the mandate here is to turn privacy primitives, zero-knowledge, and verifiable compute into everyday infrastructure: receipts, rails, and verifiable machines that other people build on without thinking about it. This document is the charter for that lab.

Each primitive is designed to be credibly scarce, permissionless, censorship-resistant, and cheap to verify. Gold condenses geology; Bitcoin condenses thermodynamics; this triad condenses the utilities of the information era into assets: things that cannot be faked and do not ask permission, cheap for anyone to verify yet costly to produce or deny. Three different hard facts, answering three different questions, none of them a later edition of another (§30: Objections & Responses).

The claim under test. Under sustained administrative and financial repression, a bearer asset may earn monetary premium if holding it preserves private settlement, portable proof, and access to verified compute after ordinary substitutes weaken. The full service path must remain stress-deliverable; demand must not bypass the asset; a persistent, self-custodied, loss-bearing holder constituency must absorb residual financial risk; and project credit must remain separate. Whether any network satisfies those conditions—or whether the triad should share one asset—is an empirical question, and this thesis is written so that the answer can be no.

The thesis will test this through a conditional chain: utility demand creates standardized work; standardized work produces receipts; receipts represent stress-deliverable service; those receipts enable markets; markets produce fee flows; fee flows support a scarce asset only under non-bypassable accrual rules; a persistent, self-custodied, loss-bearing, regime-responsive holder constituency anchors that asset; and only then, if the asset remains liquid, neutral, verifiable, legally holdable, and agency-preserving, may it earn a store-of-value premium.

Premises

The argument below is the steel-man form used on the project site and in outreach. Each premise is developed in the body; together they bound what the thesis does and does not claim.

  1. Soft guarantees are weakening. Modern money, media, and infrastructure increasingly depend on compliance systems, custodians, platforms, hardware vendors, and institutions whose guarantees are politically and technically fragile (§1: The Failure of Soft Guarantees, §2: The World Forces New Monetary Primitives).

  2. The digital economy has three unavoidable needs. A dense AI civilization needs private settlement, portable attestations, and verified compute—Privacy, Proofs, and Compute as scarce capacities, not slogans (§0: Introduction, Part II).

  3. These needs can become verifiable commodities. If workloads are standardized, outputs become receipts, and verification stays much cheaper than production, proofs and verified compute can trade as public facts rather than platform promises (§19: Layer 4: Truth & Work, Appendix A: Formal Model of Verification Asymmetry & VerifyPrice).

  4. Gross capacity is not deliverable service. Installed power and hardware are inputs, not usable output. Monetary-grade capacity is the scenario-specific surviving flow through energy, conversion, cooling, hardware, network, workload, proof, verification, settlement, and user access (§6: The Triad and the Monetary Candidate, §14: Layer 0: Verifiable Machines & Energy).

  5. A store of value requires more than utility. Indispensable services do not automatically become money; demand must accrue to a scarce asset rather than leaking to operators, hyperscalers, custodians, or fiat rails (§3: First Principles: What a SoV Must Survive, §30: Objections & Responses).

  6. Value capture requires enforceable monetary design. The asset must be required for core fees, partially burned or retired, staked as collateral, issued under discipline, and protected from bypass channels (§10: Work Credits: Energy-Anchored Claims, §27: Risk Analysis & Failure Modes).

  7. Gross native demand is not a monetary anchor. Just-in-time fee acquisition, burns, operator inventory, collateral requirements, and wrappers do not by themselves create a persistent, self-custodied, loss-bearing constituency that adds through stress (§23: Extended Telemetry).

  8. The system must remain falsifiable. Verification cost, reachability, settlement safety, decentralization, fee coverage, native-asset capture, delivered capacity, holder quality, and agency must be public telemetry—not marketing claims (§23: Extended Telemetry, §27: Risk Analysis & Failure Modes).

  9. Market price is not proof of monetary adoption. Even when the protocol loop works, observed price can be set by wrappers, leverage, dealers, and allocation rules without native use (§10: Work Credits: Energy-Anchored Claims, §23: Extended Telemetry). VerifyFlow instruments the second loop; it does not replace VerifyPrice, VerifyReach, VerifySettle, or the Native Monetary Buyer Map.

  10. Duration-neutral money is not duration finance. A repression-resistant store of value cannot be a coupon the state can pin. Civilization still needs someone to warehouse the years between pouring concrete and producing power. Project notes are explicit loss-bearing credit, not monetary backing (§2: The World Forces New Monetary Primitives, §30: Objections & Responses).

Conclusion (conditional). A base asset is only a monetary candidate. It may earn premium only if the seven-layer stack delivers usable service under stress, demand cannot bypass it, and a persistent self-custodied constituency bears loss through the relevant regime. Work Credits remain typed capacity or service claims; FCR, FER, and PIDL artifacts remain evidence; project notes remain duration-bearing credit; and LP or staking positions remain derivatives or operating claims. No useful service is promoted to money by terminology.

Contributions

This thesis makes four main contributions:

  1. Threat model and layered architecture.

    We build a threat model that assumes intentional repression rather than benevolence: financial repression (YCC, capital controls), censorship and shutdowns, hardware and identity capture, and platform-mediated reality. On top of that we propose a seven-layer “cypherpunk stack”:

    • Layer 0: Verifiable Machines & Energy

    • Layer 1: Reachability (communications & transport)

    • Layer 2: Distribution & Execution (software supply & runtime)

    • Layer 3: Identity & Claims (humans and machines without doxxing)

    • Layer 4: Truth & Work (proof systems, PoUW, VerifyPrice)

    • Layer 5: Value & Settlement (privacy rails, non-custodial flow)

    • Layer 6: Governance & Telemetry (keeping neutrality and resilience measurable)

    The rest of the thesis walks this stack from silicon and power up through proofs, settlement, and governance.

    Architecture Map: The seven-layer cypherpunk stack.
  2. Economic formalization: verification asymmetry and VerifyPrice.

    We formalize verification asymmetry as the ratio

    r(W)=v(W)p(W)r(W) = \frac{v(W)}{p(W)}

    between verification and production cost for a workload WW, and introduce VerifyPrice (a public KPI vector of p50/p95 verify times, costs, and failure rates) as the hinge that turns proofs and verified FLOPs into commodities rather than platform IOUs. This gives a quantitative basis for treating “AI Money” and “ZK Money” as analytical lenses on service demand, not for treating Work Credits as money. The associated base asset remains only a conditional monetary candidate.

  3. Modular stack: four reference applications and twelve primitives.

    We propose a Create/Compute → Prove → Settle → Verify loop and instantiate it with four reference applications (private treasury & payroll, media provenance & authenticity, verified inference, and proof/compute procurement), built on a reusable kit of primitives. These include a Proofs-as-a-Library SDK (PaL), a Privacy Rails Kit (PRK) for non-custodial settlement, Proof Interface Definition Language (PIDL) as a minimal receipt schema, MatMul-PoUW and verified-inference harnesses, canonical workload registries, multi-ZK adapters, SLA escrow/slashing, neutral routers, bridge-safety templates, and a telemetry layer that keeps useful work and neutrality measurable across chains and vendors.

  4. Telemetry, governance, and implementation playbook.

    We extend VerifyPrice into a broader observability regime, including VerifyReach (reachability under censorship) and VerifySettle (settlement success and refund safety), and propose a “no dashboards, no trust” governance posture where protocol changes and incident responses are driven by SLOs and public receipts rather than foundation fiat. We complement this with an adoption curve, an operator/investor checklist for SoV evaluation, and implementation sketches (Layer-0 hardware, privacy corridors, proof factories, developer SDKs) that make the stack actionable for builders and allocators over the next 12–36 months.

End-to-End Vignette: The Loop in Action

Before diving into theory, here is a concrete story that walks the Create/Compute → Prove → Settle → Verify loop. This vignette shows how the stack works as a felt reality, not just a framework.

Scenario: A Company Runs Private, Auditable Payroll

TechCo is a software company with employees and vendors across several jurisdictions. Its CFO needs to run payroll while preserving salary confidentiality, avoiding unnecessary exposure of the transaction graph, and giving auditors and tax authorities scoped evidence that payments were authorized, complete, and properly reported.

Step 1: Create (Intent)

The CFO opens TechCo’s treasury dashboard (built on PRK, the Privacy Rails Kit). She creates a payroll batch:

  • 47 employees

  • Total: 142,000 USD-equivalent in Work Credits

  • Policy: “Salaries are private; aggregate spend is auditable; individual amounts disclosed only with employee consent.”

The dashboard compiles this into a claim: “Pay these 47 recipients the specified amounts, under this policy, by end-of-day Friday.”

Step 2: Prove (Compliance + Privacy)

The claim is sent to PaL (Proofs-as-a-Library). PaL compiles it into two proofs:

  1. Compliance proof: A ZK proof that the batch satisfies TechCo’s internal policy (aggregate under budget, recipients are on the approved list, no single payment exceeds threshold). This proof reveals nothing about individual amounts or identities—only that the rules were followed.

  2. Integrity proof: A hash commitment binding the full payroll data. This hash is stored on-chain; the actual data stays encrypted in TechCo’s vault.

Both proofs are packaged into a PIDL receipt: claim hash, proof hashes, workload ID, SLA tier, timestamps, and a prover signature.

VerifyPrice checkpoint: The compliance proof took 2.3 seconds and cost $0.004 to generate. Independent verification takes 0.8 seconds on a laptop. This is well within the SLO (p95,t5sp_{95,t} \leq 5\text{s}, p_{95,c} \leq \0.01$).

Step 3: Settle (Private Execution)

With proofs in hand, PRK executes the payroll:

  • For employees in jurisdictions with limited banking access: atomic swap via BTC\leftrightarrowXMR corridor. TechCo’s BTC is swapped for XMR, which is sent to employee wallets. The corridor is non-custodial; if anything fails, funds return to TechCo (refund-safe).

  • For employees elsewhere: direct settlement over a shielded pool (e.g., Zcash). Each payment is encrypted; only the recipient and TechCo (via viewing keys) can see the details.

VerifySettle checkpoint:

  • Swap success rate: 98% (2 retries due to network latency, both succeeded).

  • Refund safety: 100% (all potential failures would have returned funds).

  • Time to finality: median 4 minutes, p95 11 minutes.

  • Anonymity set: 12,000+ active notes in the shielded pool.

Step 4: Verify (Audit Trail)

After settlement, the following are publicly verifiable:

  • On-chain: The PIDL receipt exists, the proofs verify, the aggregate amount was transferred at the specified time.

  • By TechCo’s auditors: Using viewing keys, auditors can see the full breakdown (who got paid how much) and confirm it matches the compliance proof.

  • By employees: Each employee can verify their own payment arrived, using their private key.

  • By anyone: The compliance proof demonstrates policy was followed, without revealing any private data.

What the adversary sees:
  • An external observer monitoring Country A sees: “TechCo moved some BTC into an XMR corridor.” They cannot see amounts, recipients, or purposes. TechCo can provide auditors and tax authorities scoped viewing keys and PIDL receipts demonstrating that payments were authorized and properly reported.

  • A competitor monitoring the blockchain sees: “Some shielded transactions occurred.” They learn nothing about TechCo’s payroll structure or employee compensation.

  • A hacker who compromises a single employee’s device sees: that employee’s payment. They cannot reconstruct the full payroll or identify other employees.

What TechCo gains:
  • Privacy: Payroll data is not exposed to competitors, data brokers, or unrelated intermediaries by default. Auditors and tax authorities receive scoped evidence via viewing keys.

  • Compliance: Auditors get cryptographic proof that policy was followed, without needing to trust TechCo’s word.

  • Resilience: Even if banks freeze accounts or exchanges delist, the privacy corridor remains operational.

  • Receipts: Every step produced a verifiable artifact (PIDL receipts, proofs) that can be archived, audited, or used in disputes.

The loop in summary:
StageWhat HappensOutput
CreateCFO defines intent + policyClaim
ProvePaL compiles compliance + integrity proofsPIDL receipt
SettlePRK executes via privacy corridorsValue transferred
VerifyAnyone can check proofs; auditors use viewing keysAudit trail

The Create/Compute → Prove → Settle → Verify loop in the payroll scenario.

This is lawful privacy: default-private, optional-disclosure, with receipts that anyone can verify. The triad (Privacy for settlement, Proofs for compliance, Compute for proof generation) works together to make the flow possible.

Variation: Media Provenance

The same loop applies to a journalist publishing a video:

  1. Create: Camera with secure element captures footage, emitting a signed provenance attestation (device ID, timestamp, geolocation hash).

  2. Prove: Edit suite issues proofs of each transformation (crop, color grade, caption). Each edit is a new PIDL receipt referencing the parent.

  3. Settle: (Optional) If the video is monetized, payment flows over privacy rails to the creator, with receipts linking payment to provenance.

  4. Verify: Any viewer or platform can verify the chain: “This video originated from camera X at time T, was edited as follows, and has not been tampered with since.” Deepfake detectors can check against registered provenances.

Platforms that strip metadata cannot strip the on-chain PIDL receipt. The proof persists even if the platform delists the content.

These vignettes are not hypothetical futures; they are the concrete scenarios the rest of this thesis is engineered to support. The stack exists to make these flows cheap, verifiable, and non-custodial under adversarial conditions.

Tip: hover a heading to reveal its permalink symbol for copying.